Skip to content

Security: InitORM/Database

Security

SECURITY.md

Security Policy

Türkçe sürüm: SECURITY.tr.md

Supported versions

Security updates are provided for the latest minor release of each InitORM package. Older minor lines may receive fixes at the maintainer's discretion.

Package Supported
initorm/orm latest 1.x
initorm/database latest 1.x
initorm/dbal latest 1.x
initorm/query-builder latest 1.x

Reporting a vulnerability

Please do not open a public issue or discussion for security vulnerabilities.

Use one of the following channels:

  1. GitHub Private Vulnerability Reporting (preferred): open a report from the Security tab of the affected package repository — for example https://github.com/InitORM/ORM/security/advisories/new.
  2. Email: info@muhammetsafak.com.tr with the subject line [InitORM Security] <package>.

Please include:

  • Affected package and version(s)
  • PHP and database driver versions
  • A description of the issue and its impact
  • Steps to reproduce (proof of concept welcome)
  • Any suggested remediation

What to expect

  • An acknowledgement within 5 business days.
  • An assessment and initial response within 14 business days.
  • A coordinated disclosure: once a fix is ready, an advisory is published with credit to the reporter unless anonymity is requested.

Thank you for helping keep InitORM and its users safe.

There aren't any published security advisories