Skip to content

Security: httptoolkit/mockttp

SECURITY.md

Security Policy

Supported Versions

The latest published version is actively supported. The preceding major version is supported for security fixes for 6 months after the first stable release of a new major version (e.g. 3.x.x is supported for 6 months after 4.0.0 is published). Security advisories and releases may be published for older unsupported major versions where convenient and valuable to do so, but this is not guaranteed. Please only report issues affecting the currently supported versions, and update to new major versions within 6 months for security support.

Reporting a Vulnerability

Vulnerabilities in Mockttp can be reported through the private GitHub security report channels. If you receive no response within 7 days, please reach out to security@httptoolkit.com.

Reported issues will be triaged, and confirmed vulnerabilities will be fixed & published as security advisories within 90 days. Advisories are published on GitHub.

Learn more about advisories related to httptoolkit/mockttp in the GitHub Advisory Database