Security Policy

July 19, 2026 ยท View on GitHub

Reporting a vulnerability

Do not report security vulnerabilities in a public issue. Report them through the Conductor private security advisory channel.

Include the affected Java SDK artifact and version, a minimal reproduction, impact, and any mitigation you identified.

Supported versions

Security fixes are applied to the current maintained release line. Please upgrade to the latest published SDK release before reporting behavior that may already be fixed.

For Conductor server support and vulnerability policy, see the upstream security policy.