| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability, please report it by emailing cmangun@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Any suggested fixes (optional)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Resolution Target: Within 30 days for critical issues
We follow responsible disclosure practices:
- Reporter notifies maintainer privately
- Maintainer acknowledges and investigates
- Fix is developed and tested
- Coordinated public disclosure after fix is available
This policy applies to:
- All code in this repository
- Configuration files and templates
- Documentation that could expose security-sensitive information
- Vulnerabilities in dependencies (report to upstream maintainers)
- Issues in example/demo configurations not intended for production use