Security policy

Supported versions

BloomPG 0.1.x on PostgreSQL 18 is the currently supported release line. The project is an analytical research extension and is not recommended as an unreviewed default on multi-tenant or security-sensitive clusters.

Reporting a vulnerability

Use GitHub’s private vulnerability reporting form in the repository’s Security tab. Do not disclose a suspected vulnerability through a public issue or discussion. Include the BloomPG commit or version, PostgreSQL minor version, operating system, a minimal reproducer, and any relevant PostgreSQL log output.

For operational boundaries, see the scope and deployment warning in README.md.