Security fixes are prepared against the latest pre-1.0 release. Older releases may not receive security updates, so users should upgrade to the latest available version before reporting a problem.
Do not open a public issue for a suspected vulnerability.
Email jpelak@gmail.com with the subject
Lemmon Validator security report. Include as much of the following information as possible:
- The affected Lemmon Validator and PHP versions
- A description of the vulnerability and its potential impact
- Steps or a minimal example that reproduces the problem
- Any known mitigations or suggested fixes
Please allow time for the report to be reviewed before public disclosure. The maintainer will coordinate with the reporter on a fix and an appropriate disclosure timeline.