Skip to content

Latest commit

 

History

History
65 lines (43 loc) · 2.12 KB

File metadata and controls

65 lines (43 loc) · 2.12 KB

Security Policy

Supported Versions

Use the following table to report vulnerabilities to the maintainers:

Version Supported
2.x.x ✅
1.x.x ❌

Reporting a Vulnerability

We prefer that severe vulnerabilities or exploits be reported by opening a Pull Request (PR) containing the fix, if possible. This allows us to review and merge the fix securely and quickly.

If you are unable to provide a fix, or if the issue is sensitive but you cannot create a PR, you may still use the Security Vulnerability Report issue template.

For standard bugs and feature requests, please use the regular Issue Tracker.


name: Security Vulnerability Report about: Report a security vulnerability to help us keep our project secure. title: "[VULN] " labels: security, vulnerability assignees: ""


Describe the Vulnerability A clear and concise description of the security vulnerability.

Affected Versions

  • Project Version(s) (e.g., 2.0.0, 2.1.5):
  • Component(s) (e.g., API, Database Integration):
  • Operating System / Environment (if relevant):

Checklist

  • I have verified that this vulnerability is not a duplicate of an existing report.
  • I have considered opening a PR with a fix instead of this issue (preferred for severe exploits).

Steps to Reproduce Steps to reproduce the behavior:

  1. Go to '...'
  2. Perform action '...'
  3. Observe vulnerability '...'

Expected Behavior A clear and concise description of what you expected to happen (i.e., the secure behavior).

Proof of Concept / Exploit Code (Optional) If applicable, provide a minimal proof of concept or exploit code that demonstrates the vulnerability. PASTE CODE HERE

Impact Describe the potential impact of this vulnerability (e.g., data breach, unauthorized access, denial of service).

Proposed Fix (Optional) If you have a suggestion for a fix or mitigation, please describe it here. Ideally, please submit a PR with this fix.

Additional Context Add any other context about the vulnerability here.