If you believe you have found a security vulnerability in this project, please follow the steps below so we can triage and remediate it quickly and safely.
- Email:
silasssdev@gmail.com
If you prefer encrypted reports, send to the same email using the project's PGP key (publish the key in this repository or provide a URL to it). If you do not have a PGP key, send the report by email and mark the message as sensitive.
Please include the following information (as much as possible):
- Affected component(s) and version(s) (example:
backend v5.1.3,web client v4.0.2) - A clear description of the issue and impact
- Steps to reproduce (minimal reproducible example or PoC)
- Expected and actual behavior
- Any exploit code or proof-of-concept (attach as patch or text)
- HTTP request/response samples, logs, or stack traces if applicable
- Your contact information and preferred disclosure method
- Whether you are willing to coordinate disclosure and share timeline constraints
- Acknowledgment: within 48 hours (we will confirm receipt and next steps).
- Initial triage / status update: within 72 hours after acknowledgment.
- Remediation plan: we will propose a remediation plan and ETA as soon as possible; target is to publish a fix or mitigation within 30 days for critical issues where feasible. If more time is required, we will provide regular status updates.
- Coordinated disclosure: we prefer to coordinate public disclosure with reporters. By default, we follow a 90-day coordinated disclosure window for critical issues unless an agreed alternative is reached.
- We will classify reported issues according to severity (Low / Medium / High / Critical) and prioritize accordingly.
- We reserve the right to accelerate disclosure for issues that are actively exploited or present an unacceptable risk if not publicly disclosed.
- Reporters who follow this policy and provide actionable reports may be credited in release notes or the repository's acknowledgments, unless they request anonymity.
- We will not publish your personal information without explicit consent.
- If you report a vulnerability in good faith and follow this policy, we will not pursue legal action against you for your findings.
- Do not exploit the vulnerability beyond what is necessary to reproduce the issue. Do not access or exfiltrate data that is not yours.
- Submit a GitHub Security Advisory (if the repository is hosted on GitHub) or open a ticket in the vendor's private security intake channel as applicable.
- For critical or emergency situations, include “CRITICAL VULNERABILITY” in the subject and call the published emergency contact number if one exists.
- We will publish release notes and, where appropriate, CVE assignments for fixed issues.
- We will work with you to coordinate public disclosure if you opt-in to coordinated disclosure.
- This policy may be updated from time to time. The latest version is the authoritative policy.
- If you are unsure whether something is a security vulnerability, please report it — we will triage.