Skip to content
Flag of Europe
Made in the European Union · Independently built · Released under EUPL 1.2

Security Policy

We build security software, so we hold our own to the same bar. Found a vulnerability? Report it responsibly — and thank you for helping keep users safe.

Report a vulnerability privately — please don't open public issues for security reports.

Email us (encrypt if you can), or open a private GitHub Security Advisory on the affected repository.

security@jsentinel.eu

Include the affected version/module, a description, and ideally a minimal proof-of-concept. Never include real user data.

What happens next

  1. Acknowledgement We confirm receipt within a few business days.
  2. Triage & assessment We reproduce, confirm and rate the issue (severity, affected versions).
  3. Fix & release A patched version ships on the affected release line.
  4. Coordinated disclosure An advisory is published once a fix is available — with credit to you, if you wish.

Scope

In scope

  • The jSentinel open-source libraries (flagship jSentinel for Java)
  • The jSentinel-* Maven artifacts on Central
  • This website (jsentinel.eu)

Out of scope

  • Third-party dependencies — please report upstream
  • Theoretical issues with no practical impact
  • Findings that require an already-compromised host

Supported versions

  • Active 00.79.x — the latest line; receives security fixes.
  • Superseded ≤ 00.78 — fixes & backports via Support & Maintenance.
Advisories — no public security advisories at this time. Published advisories will appear here and as GitHub Security Advisories on the repository.