Version | Supported |
---|---|
1.0.x | ✅ |
< 1.0 | ❌ |
If you discover a security vulnerability, please follow these steps:
- Do Not disclose the vulnerability publicly
- Send details to our security team at [email protected]
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge receipt within 24 hours and aim to:
- Confirm the vulnerability within 72 hours
- Release a fix within 30 days
- Notify you when the fix is released
Our system implements:
- Input validation and sanitization
- Rate limiting
- IP blacklisting
- Security headers
- Audit logging
- Regular security scans
- Dependency updates
- Docker security configurations
- Keep dependencies updated
- Use strong passwords
- Enable 2FA
- Follow least privilege principle
- Regular security training