This project is currently maintained on the main branch.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0.0 | ❌ |
Please report security vulnerabilities privately.
- Email: security@example.com
- Subject format:
[SECURITY] 01cloud DNS Controller - <short summary>
Please include:
- Description of the vulnerability
- Steps to reproduce (PoC if available)
- Impact assessment
- Suggested remediation (if known)
- Your contact details
- We acknowledge receipt within 3 business days.
- We triage and validate the report.
- We provide regular status updates while investigating.
- We prepare a fix and coordinate disclosure timing with the reporter.
- We publish a security advisory after remediation.
In scope:
- Source code in this repository
- Build and CI configuration in this repository
Out of scope:
- Third-party service outages
- Vulnerabilities requiring physical access to infrastructure not managed by this project
We support good-faith security research. If you act in good faith, avoid privacy violations, avoid service disruption, and provide us a reasonable time to remediate, we will not pursue legal action for your research.