Skip to content

Security: Progmasoft/catch3

Security

SECURITY.md

Security policy

Progmasoft Catch3 is an independent fork, not an official Catch2 release. Security reports for this repository must go to Progmasoft, not to upstream Catch2 maintainers.

Supported code

We triage reports against the current devel branch and the latest tagged Catch3 release. Older tags and upstream Catch2 branches are not separately maintained here. A fix may be released or documented without a backport to every earlier tag.

Private reporting

Email support@progmasoft.com with a concise description, affected revision, minimal reproduction, impact, and a safe way to reach you. Do not include credentials, private test fixtures, or exploit details in a public issue. We will coordinate disclosure after validating the report and preparing a fix or mitigation.

If the same flaw independently affects unmodified upstream Catch2, report it to its maintainers through their current security policy as a separate disclosure. Do not assume a Catch3 report reaches upstream.

There aren't any published security advisories