CondationCMS is currently under active development.
Security updates are generally provided for the latest released version. Older versions may receive security updates at the maintainers' discretion, depending on the severity of the vulnerability and the effort required to provide a safe fix.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | Generally no |
| Development snapshots | No guarantee |
Users are strongly encouraged to keep CondationCMS and all installed modules up to date.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Use one of the following private reporting channels:
- GitHub Private Vulnerability Reporting through the Security Advisory page of the affected repository.
- Email: security@condation.com
Please include as much of the following information as possible:
- the affected CondationCMS repository and version,
- the affected component or module,
- a description of the vulnerability,
- steps required to reproduce it,
- possible impact,
- known workarounds,
- proof-of-concept code or logs, where appropriate,
- whether you believe the vulnerability is currently being exploited.
Please do not include real credentials, personal information, customer data, or other sensitive data in the report.
We will make a reasonable effort to:
- acknowledge the report within five working days,
- investigate and assess the reported issue,
- keep the reporter informed about important developments,
- coordinate the publication of fixes and security advisories,
- credit the reporter when requested and appropriate.
Response times may vary because CondationCMS is currently maintained as an open-source project without guaranteed commercial support.
Please allow sufficient time for investigation and the preparation of a fix before publicly disclosing a vulnerability.
We ask reporters to coordinate public disclosure with the CondationCMS maintainers. We will aim to publish confirmed vulnerabilities together with an update, mitigation, or clear user guidance.
Security updates and relevant mitigation instructions may be published through:
- GitHub Security Advisories,
- GitHub releases,
- release notes,
- the CondationCMS website.
This policy covers the official CondationCMS core, manager, modules, extensions, distributions, and other repositories maintained by the CondationCMS organization.
Third-party modules, extensions, themes, deployment environments, and modified distributions should normally be reported to their respective maintainers unless the vulnerability originates in CondationCMS itself.