|
1 | | -# 🔐 Security Policy |
| 1 | +# Security Policy |
2 | 2 |
|
3 | | -## 📬 Reporting a Vulnerability |
| 3 | +## Supported Versions |
4 | 4 |
|
5 | | -If you discover a security issue, please report it via: |
| 5 | +The following versions of this project are currently receiving security updates: |
6 | 6 |
|
7 | | -- GitHub Security Advisory (preferred) |
8 | 7 |
|
9 | | -Do not open public issues for vulnerabilities. |
| 8 | +> **Note:** We strongly recommend upgrading to a supported version to receive the latest security patches. |
10 | 9 |
|
11 | 10 | --- |
12 | 11 |
|
13 | | -## 📌 Scope |
| 12 | +## Reporting a Vulnerability |
14 | 13 |
|
15 | | -In scope: |
16 | | -- Security vulnerabilities in the application or extension |
17 | | -- Data leaks, auth issues, or unsafe request handling |
18 | | -- AI-related issues (prompt injection, misuse, data exposure) |
| 14 | +If you discover a security vulnerability in this project, please follow the responsible disclosure process below. |
19 | 15 |
|
20 | | -Out of scope: |
21 | | -- Theoretical issues without proof |
22 | | -- Third-party services |
| 16 | +### How to Report |
| 17 | + |
| 18 | +Send a detailed report to: **w4nn4d133@gmail.com** |
| 19 | + |
| 20 | +Please include the following information in your report: |
| 21 | + |
| 22 | +- A clear description of the vulnerability |
| 23 | +- Steps to reproduce the issue |
| 24 | +- Affected version(s) |
| 25 | +- Potential impact of the vulnerability |
23 | 26 |
|
24 | 27 | --- |
25 | 28 |
|
26 | | -## ⚠️ Guidelines |
| 29 | +## What to Expect |
| 30 | + |
| 31 | +| Stage | Timeline | |
| 32 | +| ----------------------------- | ------------------- | |
| 33 | +| Acknowledgement of report | Within 48 hours | |
| 34 | +| Severity assessment (CVSS v3) | Within 5 business days | |
| 35 | +| Status update | Every 7 days | |
| 36 | +| Patch release (if accepted) | Depends on severity | |
27 | 37 |
|
28 | | -- Provide clear steps to reproduce |
29 | | -- Include proof-of-concept if possible |
30 | | -- Do not publicly disclose before a fix |
| 38 | +### If Your Vulnerability Is Accepted |
| 39 | + |
| 40 | +- You will be notified of the remediation plan and estimated fix timeline. |
| 41 | +- Credit will be given in the release notes (unless you prefer to remain anonymous). |
| 42 | +- A CVE identifier may be requested if applicable. |
| 43 | + |
| 44 | +### If Your Vulnerability Is Declined |
| 45 | + |
| 46 | +- You will receive a detailed explanation of why the report was not accepted. |
| 47 | +- You are welcome to provide additional information if you believe the decision should be reconsidered. |
31 | 48 |
|
32 | 49 | --- |
33 | 50 |
|
34 | | -## 🛡️ Note |
| 51 | +## Responsible Disclosure |
| 52 | + |
| 53 | +Please do **not** publicly disclose the vulnerability until a fix has been released or we have mutually agreed on a disclosure timeline. We are committed to working with security researchers in good faith. |
35 | 54 |
|
36 | | -This project is intended for ethical and defensive security research only. |
| 55 | +Thank you for helping keep this project secure. 🔒 |
0 commit comments