Thank you for helping keep Limoxel secure.
Security is considered a fundamental engineering responsibility of the project. Responsible disclosure helps protect users, contributors, and downstream adopters while enabling vulnerabilities to be investigated and resolved in a coordinated manner.
The following table identifies the versions currently receiving security updates.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
Only supported releases receive security fixes.
If you discover a potential security vulnerability, please do not report it publicly through GitHub Issues, Discussions, or Pull Requests.
Instead, report the issue privately by contacting:
Please include, where applicable:
- A clear description of the vulnerability.
- Steps to reproduce the issue.
- The affected version.
- The potential impact.
- Proof-of-concept code or screenshots (if appropriate).
- Suggested mitigation or remediation (optional).
Providing complete information helps us investigate and resolve issues more efficiently.
To protect users of Limoxel, we ask that security vulnerabilities remain confidential until they have been investigated and, where necessary, addressed.
Please avoid publicly disclosing security issues before the project maintainers have had a reasonable opportunity to assess and resolve them.
We are committed to working collaboratively with security researchers throughout the disclosure process.
Each reported vulnerability will undergo an engineering review.
The review process generally includes:
- Initial acknowledgement.
- Reproduction and validation.
- Impact assessment.
- Root cause analysis.
- Development of a remediation.
- Validation of the fix.
- Coordinated public disclosure when appropriate.
The exact process may vary depending on the severity and complexity of the issue.
Limoxel is developed according to the following engineering principles:
- Security is considered during design and implementation.
- Dependencies are reviewed before adoption.
- Production code is validated before release.
- Security improvements are preferred over temporary workarounds.
- Engineering quality takes precedence over release speed.
This policy applies to:
- The Limoxel source code.
- Official releases.
- GitHub repository configuration.
- CI/CD workflows.
- Project documentation where security implications exist.
Third-party dependencies remain subject to their respective maintainers and security policies.
Security-related fixes are documented through project releases and the changelog when appropriate.
Sensitive implementation details may be withheld until users have had a reasonable opportunity to update.
If you are unsure whether your finding represents a security issue, you are encouraged to contact:
before creating a public issue.
We appreciate the efforts of security researchers and contributors who responsibly disclose vulnerabilities and help improve the security of Limoxel.