This section outlines the versions of our project that currently receive security updates. We prioritize providing timely patches for actively maintained versions.
| Version | Supported | End of Life Date |
|---|---|---|
| 0.1.x | ✅ | Not Yet Defined |
Note: We strongly recommend that users stay updated with the latest supported versions to ensure they benefit from the most recent security fixes and improvements. Older, unsupported versions will not receive any further security updates.
We take security vulnerabilities very seriously. If you discover a potential security issue in our project, we encourage you to report it to us responsibly. Please follow these guidelines:
- Do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and address it. Public disclosure can put other users at risk.
- Report the vulnerability via our dedicated security contact: Please send an email to [security@yourproject.org]. Encrypt your report with our PGP key if you wish (you can find our key [link to PGP key]).
- Provide detailed information: In your report, please include the following information to help us understand and reproduce the vulnerability:
- The specific version(s) of the project affected.
- A clear and concise description of the vulnerability.
- Steps to reproduce the vulnerability.
- Potential impact of the vulnerability.
- Any suggested fixes or mitigation strategies (if you have them).
Once we receive your vulnerability report, we will:
- Acknowledge receipt: We will aim to acknowledge your report within [Number] business days to confirm that we have received it and are reviewing it.
- Investigate the issue: Our security team will investigate the reported vulnerability to assess its impact and severity. This process may take some time depending on the complexity of the issue.
- Provide updates: We will keep you informed of our progress during the investigation. You can expect an update within [Number] business days of our initial acknowledgment, and further updates as needed.
- Remediate the vulnerability: If the report is confirmed as a valid security vulnerability, we will work to develop and deploy a fix as quickly as possible.
- Public disclosure (if applicable): Once a fix is available, we will publicly disclose the vulnerability in a security advisory. This advisory will include details about the vulnerability, affected versions, and how to update. We will typically credit the reporter unless they wish to remain anonymous.
- We appreciate responsible disclosure and will do our best to address reported vulnerabilities promptly.
- We ask that you provide us with a reasonable timeframe to investigate and resolve the issue before making any public disclosures.
- We consider attempts to exploit vulnerabilities or engage in malicious activities to be unacceptable and will take appropriate action.
Thank you for helping us keep our project secure!