| Version | Supported |
|---|---|
| 2026.x | ✅ |
| < 2026.3 | ❌ |
We take security seriously. If you discover a security vulnerability in Sovra, please report it responsibly.
- Do not open a public GitHub issue for security vulnerabilities
- Use GitHub's private vulnerability reporting
- Include as much detail as possible:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: We aim to acknowledge receipt within 7 days
- Initial Assessment: Within 30 days, we will provide an initial assessment
- Resolution Timeline: We aim to resolve critical vulnerabilities within 90 days
- Disclosure: We will coordinate with you on public disclosure timing
This project implements the following security practices:
- Dependency Scanning: Dependabot monitors for vulnerable dependencies
- License Compliance: FOSSA scans for license policy violations
When deploying Sovra:
- Keep dependencies up to date
- Use environment variables for sensitive configuration
- Run with least-privilege permissions
- Enable audit logging in production
- Review and customize policies for your environment