Skip to content

Security: hammond01/Mybatis.NET

Security

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
2.0.x
1.6.x
1.5.x
< 1.0

Reporting a Vulnerability

We take the security of MyBatis.NET very seriously. If you have found a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.

How to Report

Please DO NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via email to [INSERT EMAIL HERE].

You should expect a response within 24 hours. If you have not heard back after 24 hours, please feel free to follow up.

What to Include

In your report, please include:

  1. Vulnerability Description: A clear description of the vulnerability.
  2. Steps to Reproduce: Detailed steps to reproduce the issue.
  3. Impact: The potential impact of the vulnerability.
  4. PoC (Proof of Concept): If possible, provide a proof of concept or code snippet.

Process

  1. Acknowledgement: We will acknowledge receipt of your report.
  2. Verification: We will verify the vulnerability.
  3. Fix: We will work on a fix.
  4. Release: We will release a security update.
  5. Disclosure: We will publicly disclose the vulnerability after a fix has been released and users have had time to update.

Bounties

Currently, we do not offer monetary bug bounties. However, we will happily credit you in our release notes and on our "Hall of Fame" (with your permission).

Thank you for helping keep MyBatis.NET safe!

There aren’t any published security advisories