We actively maintain and provide security updates for the following versions of smart_refresher:
| Version | Supported |
|---|---|
| 1.1.x | ✅ Yes |
| 1.0.x | ❌ No |
| < 1.0.0 | ❌ No |
Please do not open a public GitHub issue for security vulnerabilities.
We take the security of this project seriously. If you believe you have found a security vulnerability, please report it privately by emailing the maintainers at appatil595@gmail.com.
- Acknowledgment: You will receive an acknowledgment of your report within 48 hours.
- Investigation: We will investigate the issue and may contact you for further details.
- Response SLA: We aim to provide a detailed response and a proposed fix/mitigation plan within 7 business days.
- CVE Assignment: If the vulnerability is confirmed, we will coordinate with you to assign a CVE identifier and determine a public disclosure date.
- Disclosure: Once a fix is released, we will publish a security advisory.
This repository uses GitHub's native secret scanning and local pre-commit hooks to prevent the accidental commitment of sensitive credentials (API keys, tokens, etc.).
We appreciate the community's help in keeping smart_refresher secure. We ask that you give us a reasonable amount of time to resolve the issue before any public disclosure.