Security Policy
Reporting a Vulnerability
Please report security issues to GitHub Advisories.
When reporting a vulnerability please do not create a public issue as it may allow attackers to exploit the vulnerability before a fix is released.
When reporting a vulnerability please include:
- Exact details on how to reproduce the vulnerability
- A proof of concept (if possible)
- Detailed description of the vulnerability
- Fill out as much of the security advisory form as possible
- Any other details you think are relevant
We will try to respond as quickly as possible.
Supported Versions
Version | Supported |
---|---|
v4.x.x | ✅ |
v3.7.13 | ✅ |
v3.7.x | ❌ |
v3.x.x | ❌ |
v2.x.x | ❌ |
v1.x.x | ❌ |
With the release of v4, we will only be updating and patching the latest version of Zipline. We will only patch security vulnerabilities in previous versions if they are critical. We recommend upgrading to v4 as soon as possible.
EOL v3
On February 24, 2024, we announced that Zipline v3 will reach its end of life (EOL) in June 2025. After this date, we will no longer provide updates, security patches, or resolve issues for Zipline v3. We recommend upgrading to v4 as soon as possible within this timeframe.