Response Timeframes#
The table below defines the timeframes in which we expect a maintainer to respond to a reported security vulnerability. For the purposes of 'responsiveness' an acknowledgement is sufficient. There isn't an expectation that a fix will be implemented within the time frames below.
| CVE Level | Timeframe |
|---|---|
| Critical | 1 week |
| High | 2 weeks |
| Medium | 4 weeks |
| Low | 8 weeks |
| None | 16 weeks |