Currently, only the latest release branch is actively supported with security updates.
| Version | Supported |
|---|---|
| v0.x.x | ✅ |
We take the security of Database Router very seriously. Since this project handles sensitive mTLS credentials and database traffic, vulnerabilities here are critical.
If you discover a security vulnerability, please do not open a public issue.
Instead, please responsibly report it via GitHub Security Advisories by clicking "Report a vulnerability".
- A description of the vulnerability and its potential impact on the router or its clients.
- Detailed steps to reproduce the vulnerability (a proof of concept).
- The versions of the router or SDKs you are testing against.
- Any suggested mitigations or patches if you have them.
We will acknowledge receipt of your vulnerability report within 48 hours. We strive to send you regular updates about our progress. If the vulnerability is accepted, we will coordinate a rapid patch release and a coordinated public disclosure with you.