Skip to content

Security: lwe8/mhaehko

SECURITY.md

Security Policy

Introduction

Dependensia is committed to ensuring the security and integrity of our codebase and user data. This security policy outlines our guidelines and procedures for identifying, reporting, and responding to security vulnerabilities.

Supported Versions

Version Supported
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7

Reporting a Vulnerability

If you believe you have found a security vulnerability in Dependensia, please report it to us immediately. You can report vulnerabilities by:

Security Vulnerability Response

When a security vulnerability is reported, we will:

  1. Acknowledge receipt of the report within a week
  2. Assess the vulnerability and determine its severity
  3. Develop a plan to address the vulnerability
  4. Implement the plan and verify the fix
  5. Notify the reporter and the public of the vulnerability and the fix

Security Vulnerability Classification

We use the following classification system to determine the severity of security vulnerabilities:

  • Critical: Vulnerabilities that can be exploited to gain unauthorized access to sensitive data or systems
  • High: Vulnerabilities that can be exploited to cause significant disruption to our service or compromise user data
  • Medium: Vulnerabilities that can be exploited to cause moderate disruption to our service or compromise user data
  • Low: Vulnerabilities that are unlikely to be exploited or cause significant disruption to our service

Security Vulnerability Disclosure

We will disclose security vulnerabilities in accordance with our disclosure policy. We will:

  • Disclose vulnerabilities that are critical or high severity within 72 hours of verification
  • Disclose vulnerabilities that are medium or low severity within 7 days of verification
  • Provide a fix or workaround for the vulnerability whenever possible

Security Testing and Auditing

We regularly perform security testing and auditing to identify and address potential security vulnerabilities. We use a combination of automated and manual testing techniques to ensure the security and integrity of our codebase.

Compliance

We comply with all relevant laws and regulations related to security and data protection.

Security Contact

If you have any questions or concerns about our security policy, please contact us at phothinmg@disroot.org.

There aren't any published security advisories