Security updates are provided for the following versions:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take the security of DormDoc seriously. If you believe you have found a security vulnerability in this project, please do not open a public issue.
Instead, please report it privately via email:
Email: security@bitmesra.ac.in (or the maintainer's email)
Please include the following information in your report:
- Type of vulnerability (e.g., XSS, SQLi, CSRF, etc.)
- Step-by-step instructions to reproduce the vulnerability
- A proof-of-concept (PoC) if available
- The potential impact of the vulnerability
- Response: We will acknowledge your report within 48 hours.
- Triage: We will investigate and confirm the vulnerability within 5 days.
- Patch: We aim to release a fix within 14 days of confirmation, depending on the complexity.
Once the vulnerability is resolved, we will publish a security advisory and credit you for the discovery (unless you prefer to remain anonymous).