Skip to content

Security: samialtas/CSharpColorPicker

Security

SECURITY.md

Security Policy

The team takes the security of this software seriously. We appreciate your efforts to responsibly disclose your findings, and we will make every effort to address any issues in a timely manner.

🛡️ Supported Versions

Only the latest version of the code available on the main branch is actively supported with security updates.

Version Supported
latest

✍️ Reporting a Vulnerability

We are committed to working with the community to resolve security issues. If you believe you have found a security vulnerability in this project, please report it to us through one of the following methods.

Please do not report security vulnerabilities through public GitHub issues.

Option 1: GitHub Private Vulnerability Reporting (Preferred)

The best way to report a vulnerability is to use GitHub's private vulnerability reporting feature.

  1. Navigate to the main page of the repository.
  2. Under the repository name, click the Security tab.
  3. In the left sidebar, click Report a vulnerability.
  4. Fill out the form with the details of the vulnerability. Please provide as much information as possible, including:
    • A description of the vulnerability and its potential impact.
    • Steps to reproduce the issue. A minimal code sample is highly appreciated.
    • Any relevant details about your environment (e.g., .NET version, Windows version).

Option 2: Email

If you prefer, you can send an email directly to us at:

samialtas@gmail.com

Please use a clear subject line, such as "Security Vulnerability in WinForms Color Picker".

🤝 Our Commitment (What to Expect)

When you choose to report a security issue to us, we will:

  1. Acknowledge receipt of your report within 3 business days.
  2. Provide an initial assessment of the report and its severity.
  3. Work to investigate and validate the vulnerability.
  4. Keep you informed of our progress.
  5. Release a patch or update to address the issue as quickly as possible.
  6. Publicly credit you for your discovery (if you wish).

We thank you for helping to keep this project and its users safe! 🙏

There aren’t any published security advisories