Security policy

AshHooks handles webhook authentication, untrusted request bodies, signing secrets, outbound destinations, and durable delivery state. We welcome responsible reports about any weakness in those boundaries.

Supported versions

Security fixes are released for the newest minor release in the current major line.

Release line Supported
2.0.x Yes
Earlier releases No

Upgrade to a supported release before requesting a backport. Safety corrections may tighten behavior in a patch release when the previous behavior accepted unsafe input or misclassified an incomplete operation.

Report a vulnerability privately

Do not open a public issue. Use GitHub's private vulnerability report.

Please include:

Never include production secrets, credentials, or signed customer payloads. Use newly generated credentials and synthetic payload bytes. We aim to acknowledge reports within seven days and will coordinate validation, remediation, release timing, and credit with the reporter.

Security guarantees

Inbound verification

Outbound requests

Delivery state and stored data

Reportable issues

Examples include:

Host application policies, migrations, secret-manager controls, queue scheduling, and receiver-side deduplication are outside the package's enforcement boundary. Custom HTTP adapters and explicit destination-validation or bound overrides replace the corresponding built-in guarantee and should be assessed as part of the host application.

The public support and compatibility policy is recorded in ADR-0010.