Skip to content

Security: Multron-Community/Multron-Download-Manager

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest minor releases of active projects within the Multron ecosystem receive security updates.

Project Version Supported
Multron Download Manager >= 0.1.0 ✅
Core Libraries Latest main ✅

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

If you believe you have discovered a vulnerability, follow these steps:

  1. GitHub Advisory (Preferred): Navigate to the affected repository's Security tab and click Report a vulnerability to open a private advisory.
  2. Direct Contact: If advisory submission is unavailable, email the maintainers directly at security@multron.org (or contact repository owners via encrypted channels).

What to Include

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step reproduction steps or a minimal Proof of Concept (PoC).
  • Operating system and architecture where the issue was reproduced.

Response Timeline

  • Initial Acknowledgement: Within 48 hours.
  • Triage & Assessment: Within 5 business days.
  • Public Disclosure: Coordinated disclosure after a fix is verified and shipped.

There aren't any published security advisories