INCIDENT_RESPONSE.md
Last Updated: January 27, 2026.
This document outlines how the GoReleaser team responds to security incidents, critical bugs, or operational disruptions that could affect users or the trustworthiness of the project.
This plan applies to everything in the goreleaser/goreleaser repository, including code, releases, and GitHub workflows.
All security incidents are initially considered sensitive and must be reported privately and exclusively through GitHub Security Advisories.
Do not disclose incidents through issues, pull requests, or public channels.
Resolution or assessment will typically be provided within 7 business days from the report date.
All communication regarding security incidents must occur exclusively through the GitHub Security Advisories page.
Once the incident is resolved and a fix is released, we will: