Security Policy

View Source

Supported versions

Only the newest published patch in the 1.0.x series receives security fixes. Unreleased revisions, superseded patch releases, and versions older than 1.0.0 are not supported. A security fix may require upgrading to the newest patch.

VersionSupported
Latest 1.0.x patchYes
Superseded 1.0.x patchesNo
< 1.0.0No

Report a vulnerability privately

Email pcharbon70@gmail.com with the subject SimdJson security report. Do not open a public issue, pull request, discussion, or test fixture for a suspected vulnerability.

Include the affected SimdJson version and commit when known, the qualified or experimental target, reproduction steps, impact, and any suggested mitigation. Remove credentials, private JSON payloads, personal information, and production data. A minimal synthetic reproducer is preferred.

Receipt should be acknowledged within seven calendar days. The maintainer will coordinate validation, disclosure timing, a patched release or other mitigation, and credit if requested. Do not publish details until coordinated disclosure is complete.

For ordinary bugs and feature requests that have no security impact, use the public issue tracker.