Reframe ships as a rolling release: only the latest version receives security updates. Please update to the newest release before reporting an issue.
| Version | Supported |
|---|---|
| Latest release | ✅ |
| Older releases | ❌ |
Please report security issues privately — do not open a public issue or pull request, and do not disclose the problem publicly until it has been addressed.
Two ways to report, in order of preference:
- GitHub private advisory — go to the Security tab and choose Report a vulnerability. This keeps the report private and lets us collaborate on a fix and a coordinated disclosure.
- Email — maik.klotz@gmail.com with subject
Reframe security.
Please include:
- the Reframe version and OS (see Settings → About & legal for the version),
- a description of the vulnerability and its impact,
- steps to reproduce, and a proof of concept if you have one.
- Acknowledgement of your report within 5 business days.
- An initial assessment and, if valid, a target timeline for a fix.
- Credit in the release notes for the fix, unless you prefer to stay anonymous.
Thank you for helping keep Reframe and its users safe.