We release security updates for the latest tagged version of gls. Older versions are not maintained.
| Version | Supported |
|---|---|
| latest | ✅ |
| older | ❌ |
If you discover a security vulnerability in gls, please report it privately.
Do not open a public issue. Public disclosure can put users at risk before a fix is available.
- Open a private vulnerability report via GitHub: Report a vulnerability
- Alternatively, email the maintainer at
security@logando-al.dev(replace with a valid address if different).
- A clear description of the vulnerability
- Steps to reproduce, or a minimal proof of concept
- Affected versions
- Any suggested remediation
- We will acknowledge receipt of your report within 5 business days.
- We will investigate and work on a fix.
- We will keep you informed of our progress.
- Once a fix is ready, we will coordinate disclosure and credit you unless you prefer to remain anonymous.
We follow a coordinated disclosure approach:
- A security advisory will be published on GitHub after a fix is released.
- We ask reporters to allow at least 90 days before public disclosure, to give users time to update.
- Install
glsonly from the official GitHub releases page or viago install github.com/logando-al/gls@latest. - Verify release artifacts when checksums/signatures are provided.
- Keep your installed version up to date.