This security policy describes how we handle security concerns in this project, and how users and contributors can report potential vulnerabilities. We strive to ensure transparency and accountability in security matters to protect our users and the project.
If you discover a vulnerability or security issue:
- Please do not disclose it publicly to prevent potential misuse.
- Report it directly via email to: shmakovis@inbox.ru
- Provide a detailed description of the vulnerability, including:
- Steps to reproduce
- The project version where the issue was found
- Your contact information for follow-up
We commit to responding within 48 hours to acknowledge receipt of your message.
- Receiving and acknowledging the vulnerability report.
- Analyzing and assessing the risk.
- Developing a patch with subsequent testing.
- Releasing a security update.
- Notifying the public and users after the update is released.
- Maintaining a log of vulnerabilities and fixes (if applicable).
- The current main branch
developis supported. - It is recommended to upgrade to supported versions for security.
- Always use the latest stable versions of the project.
- Subscribe to security updates in the repository or use automatic update features.
- Report any suspicious activities or security concerns.
- We strive for open dialogue and timely disclosure.
- Information about critical vulnerabilities will be published after a successful patch release.
- We welcome collaboration with security researchers and the community.
- Documenting and maintaining security logs.
- Using automated tools for vulnerability scanning.
- Regular security audits and reviews.
If you have any questions or suggestions regarding the project’s security, please contact us using the details above.
Thank you for contributing to the security of our project!