| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability within Obsipano, please report it privately via email to the project maintainer. Do not disclose vulnerabilities publicly until they have been addressed.
To report a vulnerability:
- Email the maintainer at the address listed in the profile.
- Include a detailed description of the vulnerability.
- Provide steps to reproduce the issue.
- If possible, include a proof of concept.
You can expect an acknowledgment within 48 hours, and a detailed response within 5 business days regarding the next steps.
Security issues include, but are not limited to:
- Remote code execution
- Arbitrary file read/write via the application
- Injection vulnerabilities
- Unsafe deserialization
The following are not considered security vulnerabilities:
- Missing security headers in development mode
- Dependency vulnerabilities in outdated packages (please update instead)
If possible, please encrypt sensitive vulnerability reports using the maintainer's PGP key (if available).
We appreciate your help in keeping Obsipano and its users safe.