Skip to content

Security: abcdefghijessie/The-StickyNotes-App

Security

.github/SECURITY.md

Security Policy - The StickyNotes App

Supported Versions

This section provides information on which versions of StickyNotes are currently being supported with security updates.

Version Supported
1.2.x Yes
1.1.x No
1.0.x No
< 1.0 No

Reporting a Vulnerability

The StickyNotes team takes security bugs seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.

How to Report a Security Vulnerability?

If you believe you have found a security vulnerability in StickyNotes, please follow these steps to report it:

  1. Email: Send an email to [email protected]. Please do not disclose the vulnerability publicly until we have had a chance to investigate and address it.
  2. Details: Include as much information as possible about the vulnerability. This might include:
    • The version of StickyNotes you are using.
    • A description of the vulnerability and its potential impact.
    • Steps to reproduce or proof-of-concept of the vulnerability.
    • Recommendations for mitigation or a potential fix, if known.

What to Expect?

  • Our team will acknowledge receipt of your vulnerability report as soon as possible, typically within 48 hours.
  • We will work to assess the issue and determine its severity and impact on the application.
  • You will be kept informed of our progress throughout the investigation and resolution process.
  • Once the vulnerability is confirmed and resolved, an update will be released promptly.
  • We will publicly acknowledge your responsible disclosure (with your permission) in the release notes of the patched version.

Security Update Policy

When a security vulnerability is identified, the following steps will be taken:

  • A patch will be developed to fix the issue.
  • A new release of StickyNotes containing the patch will be made available as quickly as possible.
  • Users will be notified of the update through our official channels (website, social media, etc.).
  • Detailed release notes will be published, explaining the nature of the vulnerability (without revealing exploitable details) and its resolution.

General Security Practices

For users of StickyNotes, we recommend the following best practices to ensure your data remains secure:

  • Always use the latest version of StickyNotes.
  • Regularly backup your data.
  • Be cautious with third-party plugins or modifications.
  • Use strong, unique passwords for your StickyNotes account.
  • Enable two-factor authentication if available.

Thank you for helping to keep StickyNotes and its users safe!

There aren’t any published security advisories