Skip to content

Security: codecentric/spring-boot-admin

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for actively maintained release lines. Please use the latest patch release of your release line. See the project releases for available versions.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues or discussions.

Use GitHub's private vulnerability reporting to submit a report to the maintainers. Include the affected versions, clear steps to reproduce, the potential impact, and a proof of concept where practical. Reports should be specific to this project and contain enough detail for the maintainers to verify the issue. Incomplete or non-reproducible reports may not receive follow-up. If private vulnerability reporting is unavailable, contact the maintainers privately through the GitHub organization.

The maintainers will acknowledge your report and work with you to investigate and coordinate a fix and disclosure. Please allow reasonable time for a response and remediation before making details public.

Scope

This policy applies to the Spring Boot Admin project in this repository. For vulnerabilities in dependencies or other projects, please report them to the respective maintainers as well.

Learn more about advisories related to codecentric/spring-boot-admin in the GitHub Advisory Database