{"templateId":"markdown","sharedDataIds":{},"props":{"metadata":{"markdoc":{"tagList":[]},"redocly_category":"Realm","type":"markdown"},"seo":{"title":"Security vulnerability fixes","description":"OpenAPI-generated documentation tool with 24k+ stars on Github - make APIs your company's superpower.","siteUrl":"https://redocly.com","image":"/assets/redocly-card.f670aae34a39545a5ea633a540cb3a4a333a1f23bb2ed3c4a1b17a5fbcf0ac85.db81178d.png","lang":"en-US"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"security-vulnerability-fixes","__idx":0},"children":["Security vulnerability fixes"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Redocly actively monitors its product packages for known security vulnerabilities and follows a defined process to address them."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-we-detect-vulnerabilities","__idx":1},"children":["How we detect vulnerabilities"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["We run automated daily audits against the published stable versions of our packages."," ","When a vulnerability is found in the dependency tree, our engineering team triages the advisory and determines the appropriate fix."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"how-we-release-fixes","__idx":2},"children":["How we release fixes"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Redocly follows a monthly release cycle for stable versions."," ","Security fixes are released as patches between stable releases according to the following policy:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Severity"},"children":["Severity"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Release timeline"},"children":["Release timeline"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Critical"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A dedicated patch release is published as soon as the fix is ready."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["High, Moderate, Low"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Fixes are accumulated and released as a single patch within 14 days of the most recent stable release."]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["All security patches include a changeset entry in the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/realm/changelog"},"children":["changelog"]},", so you can track exactly what was fixed."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"stay-up-to-date","__idx":3},"children":["Stay up to date"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Reunite users"]}," — if your project does not pin a version in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["package.json"]},", it picks up the latest version automatically on each build."," ","If you do pin a version, update it in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["package.json"]}," and trigger a new build."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Local development users"]}," — update the version in your ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["package.json"]}," and reinstall dependencies."," ","See ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/docs/realm/get-started/upgrade-realm-version"},"children":["Upgrade product version"]}," for detailed instructions."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"report-a-vulnerability","__idx":4},"children":["Report a vulnerability"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you discover a security vulnerability in a Redocly product, please contact us at ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"mailto:security@redocly.com"},"children":["security@redocly.com"]},"."]}]},"headings":[{"value":"Security vulnerability fixes","id":"security-vulnerability-fixes","depth":1},{"value":"How we detect vulnerabilities","id":"how-we-detect-vulnerabilities","depth":2},{"value":"How we release fixes","id":"how-we-release-fixes","depth":2},{"value":"Stay up to date","id":"stay-up-to-date","depth":2},{"value":"Report a vulnerability","id":"report-a-vulnerability","depth":2}],"frontmatter":{"seo":{"title":"Security vulnerability fixes"}},"lastModified":"2026-04-15T16:08:41.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/realm/faq/security-fixes","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}