Please report security vulnerabilities to security@pgedge.com, which reaches the pgEdge security team.
Please do not open a public issue for a suspected vulnerability.
Tell us the product and version, what the impact is, and how to reproduce it. You do not need to sign anything or hold a pgEdge contract to report to us.
We acknowledge reports within five business days, tell you the outcome of our assessment, and tell you before we publish anything.
Security fixes are provided for the latest release of each product. Where a product has its own published support lifecycle, that lifecycle governs.
What is in scope, our safe harbour terms, and how we handle coordinated disclosure and CVE identifiers are all set out in the pgEdge Vulnerability Disclosure Statement:
https://docs.pgedge.com/security
You may test this software freely in an environment you control. Testing pgEdge Cloud requires prior written authorisation — see the statement.
Advisories are published under the Security tab of the repository for the affected product.