The following table lists the versions of Magma projects that currently receive security updates:
| Version | Supported |
|---|---|
| 4.x | ✅ |
| < 4.0 | ❌ |
We take the security of Magma Computing projects and @magmacomputing/tempo seriously. If you believe you have discovered a security vulnerability, please follow responsible disclosure guidelines.
Do NOT report security vulnerabilities through public GitHub issues.
Instead, please report security issues by emailing our security team at:
security@magmacomputing.com.au
Alternatively, you may submit a private security advisory through the Security tab of our GitHub repository: Submit Security Advisory.
To help us investigate and resolve the issue quickly, please include:
- A detailed description of the vulnerability and potential impact.
- Step-by-step instructions or proof-of-concept (PoC) code to reproduce the issue.
- The package name and version affected (e.g.
@magmacomputing/tempo@4.0.1). - Any potential mitigations or suggested fixes.
- Acknowledgement: We will acknowledge receipt of your vulnerability report within 48 hours.
- Assessment & Fix: We aim to assess and patch verified vulnerabilities within 7 business days.
- Public Disclosure: Public advisories and patched releases will be coordinated with the reporter after a fix is verified and deployed.
Thank you for helping keep the open-source ecosystem secure!