Skip to content

Security Policy

Reporting Vulnerabilities

If you discover a security vulnerability, please report it responsibly:

We will respond within 48 hours and work with you to resolve the issue.

Supported Versions

VersionSupported
1.4.xActive
1.3.xSecurity fixes
1.2.xCritical only
< 1.2End of life

Security Measures

  • CycloneDX SBOM generated with every release
  • GitHub CodeQL scans on all branches
  • Dependabot monitors dependencies
  • Zero runtime reflection -- reduced attack surface
  • Native AOT compatible -- "distroless" deployments supported

Supply Chain Security

Skugga's NuGet packages include:

  • SBOM (Software Bill of Materials) in CycloneDX format
  • Repository commit hash for reproducible builds
  • IsAotCompatible metadata for SDK verification

Released under the MIT License.