We actively maintain and provide security updates for the following versions of this project:
| Version | Supported |
|---|---|
| Latest | β |
| Older versions | β |
If you are using an unsupported version, please upgrade to the latest release.
We take security issues seriously and appreciate responsible disclosure.
If you discover a vulnerability, please follow these steps:
-
Do not open a public issue
-
Report it privately via:
- Email: geniussantu1983@gmail.com
- Or GitHub Security Advisories (preferred)
-
Include the following details:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
We will acknowledge receipt of your report within 48 hours.
Once a vulnerability is reported:
- We will investigate and validate the issue
- A fix will be developed and tested
- We may release a patch and/or new version
- The vulnerability may be disclosed publicly after a fix is available
- We follow responsible disclosure
- Please allow us reasonable time to fix the issue before public disclosure
- We aim to resolve critical issues as quickly as possible
To help keep this project secure:
- Keep dependencies up to date
- Avoid committing secrets or credentials
- Use environment variables for sensitive data
- Follow secure coding practices
- Review code changes carefully before merging
This project may use:
- Dependency scanning tools
- Static code analysis
- Automated security checks in CI/CD pipelines
This security policy applies only to:
- The core repository code
- Official releases and distributions
It does not cover:
- Third-party dependencies (report to respective maintainers)
- Misconfigurations in user environments
We appreciate the efforts of security researchers and contributors who help improve the safety of this project.
(If desired, we may publicly acknowledge reporters who responsibly disclose vulnerabilities.)
By reporting vulnerabilities or contributing fixes, you agree that your contributions will be licensed under the same license as this project.