Skip to content

Security: mcontartesi/websocket-serverless

SECURITY.md

Security Policy

Supported Versions

Security patches and updates are maintained for the following versions of WebSocket Serverless:

Version Supported
1.x.x Yes
< 1.0.0 No

Reporting a Vulnerability

Security reports are taken seriously. If you discover a security vulnerability or potential threat, please report it responsibly:

  1. Do not open a public GitHub issue for security vulnerabilities.
  2. Report your findings directly to the project maintainer Maximiliano Contartesi via GitHub (@mcontartesi).
  3. Include detailed steps to reproduce the issue, proof-of-concept code, or HTTP request trace where applicable.

Response Process

  • Acknowledgment: You will receive an initial response within 24 to 48 hours acknowledging receipt of your report.
  • Investigation: The issue will be investigated and verified.
  • Fix & Disclosure: A security patch will be prepared and published via a patch release. Public disclosure will be coordinated after the patch is published.

There aren't any published security advisories