Security fixes are considered for the latest release and the current default branch. Older releases may need an upgrade to receive a fix. Check the releases for published updates.
Please use GitHub's private vulnerability reporting to report a suspected vulnerability. If that route is unavailable, contact the maintainer privately through the LikeHopper GitHub profile. Do not open a public issue or discussion before a fix or disclosure plan is agreed.
Include the affected plugin and Redmine versions, database engine, reproduction steps, impact, and a minimal proof of concept if available. Remove credentials and personal or customer data. The maintainer will review the report, coordinate validation and remediation, and discuss disclosure timing with the reporter. No response or fix deadline is promised.