Skip to content

Security: merionyx/api-gateway

SECURITY.md

Security policy

Thank you for helping keep this project and its users safe.

Supported versions

Security fixes are applied to the default branch (main) and, when applicable, backported to the latest release line. Older tags may not receive patches—upgrade to a current release when possible.

Reporting a vulnerability

Please do not open a public issue for security vulnerabilities.

Preferred options (use whichever you can access):

  1. GitHub — use private vulnerability reporting for this repository (Security → Report a vulnerability).
  2. Email — send details to security@merionyx.com.

Include:

  • A short description of the issue and its impact
  • Steps to reproduce (or a proof-of-concept), if safe to share
  • Affected versions or components, if known

We aim to acknowledge reports within a few business days and will work with you on a coordinated disclosure and fix timeline when reasonable.

Scope

In scope: vulnerabilities in this repository’s code, default configurations shipped here, and documented deployment paths.

Out of scope: third-party dependencies unless the issue is exploitable through this project’s usage; general security advice unrelated to a specific defect; social engineering.

There aren't any published security advisories