Use this section to tell people about which versions of your project are currently being supported with security updates.
Version | Supported |
---|---|
1.x | ✅ |
< 0.5 | ❌ |
< 0.3 | ✅ |
< 0.2 | ❌ |
If you discover a security vulnerability, we encourage you to report it responsibly. Here’s how you can report a vulnerability and what you can expect during the process:
How to Report Email:
Send an email to our security team at [email protected] Include as much detail as possible about the vulnerability, including steps to reproduce it, potential impact, and any relevant screenshots or logs. GitHub Security Advisories:
If the vulnerability is related to a repository on GitHub, you can report it using GitHub's security advisories feature. Navigate to the repository and go to the "Security" tab, then click on "Report a vulnerability". What to Expect Acknowledgment:
You will receive an acknowledgment of your report within 48 hours. This acknowledgment will include a tracking number for your report. Initial Assessment:
Our security team will conduct an initial assessment of the reported vulnerability within 7 days. During this period, we may reach out to you for additional information. Regular Updates:
You can expect updates on the status of your report every 14 days. We will inform you if there are any delays or if we need more time for a thorough investigation. Resolution:
If the vulnerability is accepted, we will work on a fix and plan for a release. You will be notified once the fix is deployed. If the vulnerability is declined, we will provide a detailed explanation of why it was not accepted. Credit:
If the vulnerability is accepted and fixed, we are happy to give you credit on our security page, unless you wish to remain anonymous.
Important Notes Please do not publicly disclose the vulnerability until we have had a chance to address it. We appreciate your patience and cooperation throughout the process. Your efforts to help us improve our security are greatly appreciated. Thank you for your responsible disclosure.