Skip to content

Security: structr/structr

SECURITY.md

Security Policy

Supported Versions

The following Structr versions are currently supported with security updates:

Version Supported End of Life (EOL)
6.x βœ… 31-DEC-2027
5.x βœ… 31-DEC-2026
4.2.x βœ… 31-DEC-2025
4.1.x ❌ 31-DEC-2024
4.0.x ❌ 31-DEC-2023
3.6.x ❌ 31-JUL-2023
< 3.5.0 ❌ 31-DEC-2022
4.3-SNAPSHOT ❌ Not ready for production

Only supported versions receive security fixes.


Reporting Security Vulnerabilities

If you discover a security vulnerability in Structr, please report it responsibly.

Do not disclose security issues publicly until they have been reviewed and addressed.


Contact

Please report security vulnerabilities via email:

security-incident-report@structr.com

Include the following information where possible:

  • A description of the issue
  • Steps to reproduce
  • Potential impact
  • Affected versions
  • Any proof-of-concept or relevant logs

Handling Process

  • Reports are acknowledged as quickly as possible
  • You will receive regular status updates (at least daily)
  • Issues are assessed and prioritized immediately
  • In case of acceptance, a security patch is typically provided within 48 hours
  • Fixes are released responsibly
  • Credit may be given to reporters upon request

For non-trivial vulnerabilities, bug bounties may be offered at the discretion of Structr GmbH.


Commercial Support

Structr GmbH offers commercial services related to security, including:

  • Security consulting
  • Hardening recommendations
  • Assisted upgrades and patching
  • Support for enterprise and public-sector deployments

For commercial inquiries, please contact:

Structr GmbH
https://structr.com
info@structr.com

There aren’t any published security advisories