Feature/3.6.0#14
Closed
charlesoj6205 wants to merge 2 commits into
Closed
Conversation
Updated the security policy to clarify supported versions and reporting process.
Contributor
There was a problem hiding this comment.
Pull request overview
Adds a SECURITY.md policy file to document supported versions and provide a private vulnerability reporting channel for this library.
Changes:
- Introduces
SECURITY.mdwith a supported-version matrix. - Documents the process for reporting vulnerabilities via email.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| @@ -0,0 +1,15 @@ | |||
|
|
|||
| We maintain updates and patches in the latest release. Earlier versions will still work, but will have less functionalities than later versions. | |||
| Thank you for letting us know about possible security vulnerabilities to this project. | ||
| Please don’t publish details in a public issue or PR, send us a private email at support@approov.io. Please disclose which version your report refers to. | ||
|
|
||
| Your message will recieve a prompt reply. |
Comment on lines
+5
to
+8
| | Version | Supported | | ||
| | ------- | ------------------ | | ||
| | 3.5.x | :white_check_mark: | | ||
| | < 3.4 | :x: | |
Contributor
|
Superseded. Its only net change over |
ivolz
added a commit
that referenced
this pull request
Jun 21, 2026
… 3.5.7 java.net.URL is immutable once the connection is opened, and the automated query-substitution path broke the request-mutation tracking message signing relies on. Removed the public API (addSubstitutionQueryParam, removeSubstitutionQueryParam, getSubstitutionQueryParams, substituteQueryParams, substituteQueryParam) and the automated substitution in the addApproov flow. Secure-string query values are now fetched manually via fetchSecureString() and built into the URL before openConnection(). USAGE.md/REFERENCE.md updated. BREAKING CHANGE: query-parameter substitution APIs removed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Merged security PR