Skip to content

Security: Simplea/xperience-community-content-sync-toolkit

Security

SECURITY.md

Security policy

Supported versions

Security fixes are provided for the latest published Content Sync Toolkit version. Prerelease versions are supported on a best-effort basis until the first stable release.

Reporting a vulnerability

Do not open a public issue for a suspected vulnerability. Use GitHub private vulnerability reporting to contact the maintainers privately.

Include the Content Sync Toolkit version, Xperience version, affected feature, impact, and reproduction steps. Do not include real content, connection strings, credentials, or other customer data. Use sanitized examples only.

The maintainers will acknowledge the report, investigate it, and coordinate a fix and disclosure timeline with the reporter. Please allow a reasonable remediation period before public disclosure.

Security scope

Content Sync Toolkit is maintained by Andres Villenas and SimpleA and is not an official Kentico product. Reports concerning Xperience by Kentico itself should be submitted through Kentico's official security channels.

There aren't any published security advisories