Skip to content

Security: Java-Lava-Bot/V2-Website

SECURITY.md

Security Policy

Supported Versions

Java Lava's website only supports the latest commits so like v2.1+ is supported right this minute

Version Supported Version
2.1.x Master
2.0.x Master
2.2.x Beta
< 2.1 Beta

Reporting a Vulnerability

Java Lava's development team will make sure to investigate security vulnerabilities reported. Here is what we will do.

  1. Receive the security vulnerability notification.
  2. Acknowledgment of vulnerability report within 24 hours of report.
  3. Investigate the report and files affected.
  4. Get back to the user who reported the vulnerability if it is confirmed, and if it is, if we are working on a fix, or if it is a package vulnerability that is out of our control.
  5. If the vulnerability is confirmed we will alert the user that a fix is being worked on and will be finished within 2 weeks, depending on the CVE severity.
  6. Depending on the severity, we will get a fix out within 2 weeks at max
  7. We will report it in the discord server and send what was the vulnerability score after it gets fixed.

There aren't any published security advisories