Security fixes are provided for the latest released minor version. Older releases may receive a fix when the vulnerability is severe and a safe backport is practical. PHP versions that no longer receive upstream security fixes are compatibility targets, not recommended production runtimes.
Do not open a public issue for a suspected vulnerability or include credentials, access tokens, personal data, or exploit details in public discussions.
Use GitHub's Report a vulnerability form in the repository Security tab to create a private security advisory. Include the affected version, impact, reproduction steps, and any suggested remediation. Fleetbase will acknowledge the report, assess severity, coordinate a fix and disclosure date, and credit the reporter if requested.
If private vulnerability reporting is unavailable, contact Fleetbase through the security contact published at fleetbase.io and reference this repository without sending secrets in the first message.