Do not include vulnerability details in a public issue, discussion, or pull request.
Use GitHub's private vulnerability reporting form:
https://github.com/cordum-io/cordum/security/advisories/new
If that form is unavailable, use the current contact method published at:
https://cordum.io/.well-known/security.txt
Check the security.txt file immediately before sending because its contact details may change. Cordum does not currently publish a PGP key for vulnerability reports. If you require encrypted reporting, use GitHub's private form.
Please include enough information for us to reproduce and assess the issue:
- the affected Cordum version or commit;
- the affected component and configuration;
- the security impact;
- clear reproduction steps or a minimal proof of concept;
- relevant logs with credentials, tokens, personal data, and other secrets removed; and
- any planned disclosure date or coordination constraints.
We aim to:
- acknowledge a report within 3 business days; and
- provide an initial triage update within 7 business days.
Our response times are targets, not service-level agreements. Investigation, remediation, release, and coordinated-disclosure timing are decided case by case based on impact, complexity, affected versions, and reporter coordination. We will communicate material changes through the private reporting channel.
| Version | Security support |
|---|---|
| 1.1.x | Active |
| 1.0.x | Security fixes only |
| Earlier than 1.0 | Not supported |
Install the latest available patch release in a supported line before reporting an issue that may already be fixed.
Cordum does not operate a formal vulnerability-reward program. This policy does not promise payment, rewards, public credit, or future work. Any recognition is discussed case by case and only with the reporter's consent.
This document describes vulnerability reporting and release support. It is not a certification or independent security audit, and it makes no compliance claim.
Last reviewed: 2026-07-13