summaryrefslogtreecommitdiff
path: root/SECURITY.txt
blob: 9ccdecb4bcb55d8d218ba08cf9ccd9452df44c95 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
# Security Policy

## Supported Versions

|Version|Supported|
|-------|---------|
| 3.x   | ✅ Yes  |
| < 3.0 | ❌ No   |

---

## Reporting a Vulnerability

If you discover a security vulnerability, **do not open a public issue**.
Instead:

1. **Email** your report to [[email protected]](mailto:[email protected]).
  Include:
  - A detailed description of the vulnerability
  - Steps to reproduce
  - Any relevant context (e.g., affected versions, environment)
2. **Response Time**: We will acknowledge your report within **3 business days**
  and keep you updated on the progress.
3. **Resolution**: If confirmed, we will:
  - Provide an estimated timeline for a fix
  - Work with you to verify the resolution
  - Credit you for the discovery (if you wish)
4. **Declined Reports**: If the report is invalid or out of scope, we will
  explain why and close the issue.

---

**Thank you for helping improve the security of our project!**