Security fixes are applied to the latest release of pactiac and pactia on the main branch.
| Component | Supported |
|---|---|
| pactiac (latest release) | Yes |
| pactia package manager (latest release) | Yes |
| spec (documentation only) | N/A |
Do not open a public GitHub issue for security-sensitive reports.
Email security reports to the maintainers (add your contact address before publishing this repo) or use GitHub private vulnerability reporting when enabled.
Include:
- Affected component (
pactiac,pactia, registry, or extension) - Steps to reproduce
- Impact assessment (code execution, path traversal, credential leak, etc.)
We aim to acknowledge reports within 72 hours.