mime-types-data Security ↑

LLM-Generated Security Report Policy ↑

Absolutely no security reports will be accepted that have been generated solely by LLM agents. There must be a human that confirms the issue.

Supported Versions ↑

Security reports are accepted for the most recent major release, with a limited window of support after the initial major release.

All issues raised must be demonstrated on the minimum supported Ruby version.

Reporting a Vulnerability ↑

Report vulnerabilities via the Tidelift security contact. Tidelift will coordinate the fix and disclosure.

Alternatively, create a private vulnerability report with GitHub.