forecast-os is pre-1.0 and ships fixes on the latest minor release line only. Security updates are published against the most recent minor version; please upgrade before reporting.
| Version | Supported |
|---|---|
| 0.7.x | ✅ |
| < 0.7 | ❌ |
Please report security issues privately — do not open a public issue or pull request for anything that could be exploited.
Email the maintainer directly at cubanmiles0@gmail.com with:
- a description of the vulnerability and its impact,
- the affected version(s),
- steps (or a minimal proof of concept) to reproduce it, and
- any suggested remediation, if you have one.
You can expect an acknowledgement within 72 hours. We will work with you to confirm the issue, prepare a fix on the supported release line, and coordinate a disclosure timeline. We are happy to credit reporters in the release notes unless you prefer to remain anonymous.
Thank you for helping keep forecast-os and its users safe.