Security Policy
We build security software, so we hold our own to the same bar. Found a vulnerability? Report it responsibly — and thank you for helping keep users safe.
Report a vulnerability privately — please don't open public issues for security reports.
Email us (encrypt if you can), or open a private GitHub Security Advisory on the affected repository.
security@jsentinel.euInclude the affected version/module, a description, and ideally a minimal proof-of-concept. Never include real user data.
What happens next
- Acknowledgement We confirm receipt within a few business days.
- Triage & assessment We reproduce, confirm and rate the issue (severity, affected versions).
- Fix & release A patched version ships on the affected release line.
- Coordinated disclosure An advisory is published once a fix is available — with credit to you, if you wish.
Scope
In scope
- The jSentinel open-source libraries (flagship jSentinel for Java)
- The
jSentinel-*Maven artifacts on Central - This website (
jsentinel.eu)
Out of scope
- Third-party dependencies — please report upstream
- Theoretical issues with no practical impact
- Findings that require an already-compromised host
Supported versions
- Active 00.79.x — the latest line; receives security fixes.
- Superseded ≤ 00.78 — fixes & backports via Support & Maintenance.
Advisories — no public security advisories at this time. Published
advisories will appear here and as GitHub Security Advisories on the
repository.