Document which versions receive security updates per project, or state that support is limited to the default branch / latest release.
| Version | Supported |
|---|---|
| latest | ✅ |
| older | ❌ |
Please do not open a public Issue for security vulnerabilities.
If enabled for the repository, use Security → Report a vulnerability on the repository page.
b4mosscommunity@b4m.co.jp
Please include:
- Affected repository and version / commit
- Description of the issue and impact
- Steps to reproduce or a proof of concept (if available)
- Any suggested fix (optional)
- We will acknowledge receipt within 1 business day.
- We will provide an initial assessment within 3 business days.
- If confirmed, we will work on a fix and coordinated disclosure.
- We may ask for more information or a CVE request when appropriate.
In scope examples:
- Authentication / authorization flaws
- Remote code execution, injection, path traversal
- Sensitive data exposure
Out of scope examples (unless otherwise noted):
- Denial of service that requires unrealistic resources
- Issues only present in outdated / unsupported versions
- Social engineering against individuals
Our disclosure policy is as follows:
- Please refrain from public disclosure until a fixed version for the reported vulnerability has been published.
- We aim to publish a fixed version within 30 days after the report. If that
is difficult, we may extend the timeline.
- In that case we will contact you again, and we may ask you to extend the disclosure hold after discussion.