Skip to content

Security: ivankuznetsov/rails_simple_auth

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

Do not report security vulnerabilities through public GitHub issues.

Email security reports to the maintainer directly. You can find contact info on the RubyGems page.

Please include:

  • Type of vulnerability
  • Steps to reproduce
  • Impact assessment
  • Proof-of-concept (if possible)

Response Timeline

  • Acknowledgment: within 48 hours
  • Assessment: within 7 days
  • Fix and disclosure: coordinated with reporter

Security Best Practices

  1. Always use HTTPS in production
  2. Set appropriate session expiry times
  3. Keep the gem updated
  4. Use environment variables for secrets

There aren’t any published security advisories