mime-types-data Security

LLM-Generated Security Report Policy

Absolutely no security reports will be accepted that have been generated solely by LLM agents. There must be a human that confirms the issue.

Supported Versions

Security reports are accepted for the most recent major release, with a limited window of support after the initial major release.

All issues raised must be demonstrated on the minimum supported Ruby version.

Reporting a Vulnerability

Report vulnerabilities via the Tidelift security contact. Tidelift will coordinate the fix and disclosure.

Alternatively, create a private vulnerability report with GitHub.