If you believe you've found a security vulnerability in any Yii.Rocks package, please do not open a public issue.
Instead, use GitHub's private vulnerability reporting on the affected repository:
- Go to the repository's Security tab.
- Click Report a vulnerability.
This opens a private advisory visible only to you and the maintainers, so the issue can be discussed and fixed before it's disclosed publicly.
Each package supports the latest major release. Security fixes are backported at the maintainers' discretion — check the individual repository's composer.json for currently supported PHP and Yii versions.