Skip to content

Security: unhield/limoxel

SECURITY.md

Security Policy

Thank you for helping keep Limoxel secure.

Security is considered a fundamental engineering responsibility of the project. Responsible disclosure helps protect users, contributors, and downstream adopters while enabling vulnerabilities to be investigated and resolved in a coordinated manner.


Supported Versions

The following table identifies the versions currently receiving security updates.

Version Supported
1.x
< 1.0

Only supported releases receive security fixes.


Reporting a Security Vulnerability

If you discover a potential security vulnerability, please do not report it publicly through GitHub Issues, Discussions, or Pull Requests.

Instead, report the issue privately by contacting:

hello.limoxel@gmail.com

Please include, where applicable:

  • A clear description of the vulnerability.
  • Steps to reproduce the issue.
  • The affected version.
  • The potential impact.
  • Proof-of-concept code or screenshots (if appropriate).
  • Suggested mitigation or remediation (optional).

Providing complete information helps us investigate and resolve issues more efficiently.


Responsible Disclosure

To protect users of Limoxel, we ask that security vulnerabilities remain confidential until they have been investigated and, where necessary, addressed.

Please avoid publicly disclosing security issues before the project maintainers have had a reasonable opportunity to assess and resolve them.

We are committed to working collaboratively with security researchers throughout the disclosure process.


Security Review Process

Each reported vulnerability will undergo an engineering review.

The review process generally includes:

  1. Initial acknowledgement.
  2. Reproduction and validation.
  3. Impact assessment.
  4. Root cause analysis.
  5. Development of a remediation.
  6. Validation of the fix.
  7. Coordinated public disclosure when appropriate.

The exact process may vary depending on the severity and complexity of the issue.


Security Principles

Limoxel is developed according to the following engineering principles:

  • Security is considered during design and implementation.
  • Dependencies are reviewed before adoption.
  • Production code is validated before release.
  • Security improvements are preferred over temporary workarounds.
  • Engineering quality takes precedence over release speed.

Scope

This policy applies to:

  • The Limoxel source code.
  • Official releases.
  • GitHub repository configuration.
  • CI/CD workflows.
  • Project documentation where security implications exist.

Third-party dependencies remain subject to their respective maintainers and security policies.


Security Updates

Security-related fixes are documented through project releases and the changelog when appropriate.

Sensitive implementation details may be withheld until users have had a reasonable opportunity to update.


Questions

If you are unsure whether your finding represents a security issue, you are encouraged to contact:

hello.limoxel@gmail.com

before creating a public issue.


Acknowledgement

We appreciate the efforts of security researchers and contributors who responsibly disclose vulnerabilities and help improve the security of Limoxel.

There aren't any published security advisories