| Version | Supported |
|---|---|
| Latest | Yes |
| Older | No |
Only the latest release is supported with security updates.
If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public GitHub issue.
- Email the maintainers at security@tibco.com with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- You will receive an acknowledgment within 5 business days.
- A fix will be developed privately and released as soon as possible.
- Always set a unique
SESSION_SECRETenvironment variable in production. - Keep dependencies up to date and run
npm auditregularly. - Use HTTPS in production deployments.
- Restrict Kubernetes RBAC permissions to the minimum required.