We take vulnerabilities seriously.
Use GitHub Security Advisories (private vulnerability reporting) for security reports.
Do not publish exploitable details in public issues.
- affected component;
- potential impact;
- reproduction steps;
- version/commit used;
- mitigation suggestion (if any).
- Initial screening: up to 5 business days.
- Correction plan: up to 15 business days for valid cases.
No SLA on Community edition.
- AMP Community repository.
- Does not cover third-party local customizations.