Security patches and updates are maintained for the following versions of WebSocket Serverless:
| Version | Supported |
|---|---|
| 1.x.x | Yes |
| < 1.0.0 | No |
Security reports are taken seriously. If you discover a security vulnerability or potential threat, please report it responsibly:
- Do not open a public GitHub issue for security vulnerabilities.
- Report your findings directly to the project maintainer Maximiliano Contartesi via GitHub (@mcontartesi).
- Include detailed steps to reproduce the issue, proof-of-concept code, or HTTP request trace where applicable.
- Acknowledgment: You will receive an initial response within 24 to 48 hours acknowledging receipt of your report.
- Investigation: The issue will be investigated and verified.
- Fix & Disclosure: A security patch will be prepared and published via a patch release. Public disclosure will be coordinated after the patch is published.