Milpa Framework is pre-1.0. Only the latest 0.x release line receives security fixes.
Note that this repository is a starting-point template — you scaffold an app from it with
composer create-project milpa/framework, then own the result. Fixes here protect the generated
starting point; the security of an app you have grown from it is yours to maintain (keep the
milpa/* dependencies updated — that is where the framework's own advisories land).
Please report security vulnerabilities privately via GitHub Security Advisories — the repository's Security tab → Report a vulnerability — rather than opening a public issue or pull request.
We aim to acknowledge a report within 72 hours and to keep you informed as we work on a fix. Once a fix is released, we will credit the reporter unless anonymity is requested.
Milpa is developed and maintained by TeamX Agency.