We are currently in active development. We provide security support for the latest minor versions.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
If you believe you have found a security vulnerability in @rut-toolkit (such as ReDoS in our parsing algorithms, prototype pollution, etc.), please responsibly disclose it. Do not open a public issue.
You can report the vulnerability directly through GitHub's native Private Vulnerability Reporting:
- Go to the Security tab of this repository.
- Click on Advisories in the left sidebar.
- Click the Report a vulnerability button.
- Fill out the form with the necessary details, reproduction steps, and potential impact.
Alternatively, you can report it by sending an email directly to matcastaneda.oss@gmail.com. This ensures that the information remains confidential and secure until we can address the issue.
- Acknowledge: We will acknowledge receipt of your report within 48 hours.
- Fix: We will prioritize a fix for any critical vulnerabilities and provide a patch release as soon as possible.
- Credit: We will publicly provide credit to the reporter in our GitHub security advisories and release notes (unless you prefer to remain anonymous).