Skip to content

Security: GreensVilla/QasidRelay

Security

SECURITY.md

Security policy

Supported versions

QasidRelay is in early development. Security fixes are accepted on main until versioned releases begin.

Reporting a vulnerability

Please do not open a public GitHub issue for vulnerabilities.

Report privately to the repository maintainers through GitHub's private vulnerability reporting flow when enabled, or contact the GreensVilla maintainers directly.

Include:

  • affected version or commit;
  • reproduction steps;
  • impact;
  • whether SMS could be sent without authorization;
  • whether secrets, OTPs, or phone numbers could be exposed.

Sensitive data rules

Do not include real OTPs, real recipient phone numbers, SIM identifiers, API keys, shared secrets, screenshots containing OTPs, or carrier account details in issues, pull requests, logs, or examples.

There aren't any published security advisories