|
1 | | -# **Security Policy** |
| 1 | +## Security Policy |
2 | 2 |
|
3 | | -## Supported Versions |
| 3 | +### Reporting Vulnerabilities |
4 | 4 |
|
5 | | -The following versions of this project are currently receiving security updates: |
| 5 | +If you discover any security vulnerabilities, please report them responsibly. |
6 | 6 |
|
| 7 | +Send detailed vulnerability reports to: |
7 | 8 |
|
8 | | -> **Note:** We strongly recommend upgrading to a supported version to receive the latest security patches. |
| 9 | +Email: w4nn4d133@gmail.com |
9 | 10 |
|
10 | | ---- |
| 11 | +OpenPGP Fingerprint: |
| 12 | +`DEBE5591C54E947279C14A6BF53D272DA9ADAF98` |
11 | 13 |
|
12 | | -## Reporting a Vulnerability |
| 14 | +Public Key: |
| 15 | +https://keys.openpgp.org/vks/v1/by-fingerprint/DEBE5591C54E947279C14A6BF53D272DA9ADAF98 |
13 | 16 |
|
14 | | -If you discover a security vulnerability in this project, please follow the responsible disclosure process below. |
| 17 | +Alternatively, you may submit your report through our official advisory channel (if available). |
15 | 18 |
|
16 | | -### How to Report |
| 19 | +### Guidelines for Reporting |
17 | 20 |
|
18 | | -Send a detailed report to: **w4nn4d133@gmail.com** |
19 | | - |
20 | | -Please include the following information in your report: |
| 21 | +Please include: |
21 | 22 |
|
22 | 23 | - A clear description of the vulnerability |
23 | 24 | - Steps to reproduce the issue |
24 | | -- Affected version(s) |
25 | | -- Potential impact of the vulnerability |
26 | | - |
27 | | ---- |
28 | | - |
29 | | -## What to Expect |
30 | | - |
31 | | -| Stage | Timeline | |
32 | | -| ----------------------------- | ------------------- | |
33 | | -| Acknowledgement of report | Within 48 hours | |
34 | | -| Severity assessment (CVSS v3) | Within 5 business days | |
35 | | -| Status update | Every 7 days | |
36 | | -| Patch release (if accepted) | Depends on severity | |
37 | | - |
38 | | -### If Your Vulnerability Is Accepted |
39 | | - |
40 | | -- You will be notified of the remediation plan and estimated fix timeline. |
41 | | -- Credit will be given in the release notes (unless you prefer to remain anonymous). |
42 | | -- A CVE identifier may be requested if applicable. |
43 | | - |
44 | | -### If Your Vulnerability Is Declined |
45 | | - |
46 | | -- You will receive a detailed explanation of why the report was not accepted. |
47 | | -- You are welcome to provide additional information if you believe the decision should be reconsidered. |
48 | | - |
49 | | ---- |
50 | | - |
51 | | -## Responsible Disclosure |
52 | | - |
53 | | -Please do **not** publicly disclose the vulnerability until a fix has been released or we have mutually agreed on a disclosure timeline. We are committed to working with security researchers in good faith. |
| 25 | +- Proof-of-Concept (PoC), if possible |
| 26 | +- The potential security impact |
| 27 | +- Affected versions/components |
54 | 28 |
|
55 | | -Thank you for helping keep this project secure. |
| 29 | +We appreciate responsible disclosure and will work to validate and address legitimate security issues promptly. |
0 commit comments