@hailbytes/sbom-diff is a supply-chain security tool, so we hold its own
supply chain to the same standard. This document explains which versions we
support and how to report a vulnerability.
Security fixes are released for the latest published 1.x version. Please
upgrade to the newest release before reporting an issue.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Instead, use GitHub's private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability (Private vulnerability reporting).
- Provide as much detail as you can — see below.
If you are unable to use private reporting, email security@hailbytes.com with the details.
- A description of the vulnerability and its impact.
- Steps to reproduce (a minimal SBOM input or command line is ideal).
- The affected version(s) and platform.
- Any known workarounds or suggested fixes.
- We will acknowledge your report within 3 business days.
- We will provide an assessment and expected timeline within 10 business days.
- We will keep you informed as we work on a fix and coordinate disclosure.
- With your permission, we will credit you once the fix is released.
Thank you for helping keep @hailbytes/sbom-diff and its users secure.