Security fixes are provided for the latest published minor release line.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
Please do not open public GitHub issues for security vulnerabilities.
Report vulnerabilities privately through GitHub Security Advisories:
- Go to the repository's Security tab.
- Click Report a vulnerability (Private vulnerability reporting).
- Provide a description, affected versions, reproduction steps, and impact.
If you cannot use GitHub Security Advisories, open a minimal issue asking a maintainer to contact you privately — without disclosing the vulnerability.
- Acknowledgement: within 5 business days.
- Assessment & triage: we validate the report and determine severity.
- Fix & disclosure: we aim to release a fix and publish a coordinated advisory promptly; we will credit reporters who wish to be acknowledged.
This policy covers the code published by this library (the constructs and
property injectors under src/). Issues in aws-cdk-lib, constructs, or
other upstream dependencies should be reported to their respective projects.
For documentation of the library's built-in security features and compliance posture, see docs/SECURITY.md.