Skip to content

Security: Gaurav-Gosain/tuios

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are only applied to the latest commit on the default branch.
As there is no stable release yet, users are encouraged to always update to the latest version.

Version Supported
Latest (main branch)
Tagged pre-releases ⚠️ Best effort
Older commits ❌ Not supported

Reporting a Vulnerability

If you discover a potential security issue in TUIOS, please do not open a public issue.
Instead, report it privately by emailing:

📧 [email protected]

When reporting, please include:

  • A clear description of the vulnerability.
  • Steps to reproduce (if applicable).
  • Affected platform and installation method (e.g., Docker, Homebrew, Nix, etc.).
  • The commit hash or version tag you tested on.

If you prefer, you may encrypt your message using GPG (optional).


Response Process

This project is maintained in personal free time, so there are no guaranteed response times.
However:

  • Reports will be acknowledged when possible.
  • The issue will be investigated as soon as time allows.
  • If confirmed, a fix will be developed and merged into the main branch.

Critical or high-impact issues may be prioritized depending on severity.


Disclosure Policy

Please avoid publicly disclosing any details of a security vulnerability until:

  • A fix has been published, or
  • You have received explicit permission to disclose.

Your responsible disclosure helps maintain project integrity and protects other users.


Thank you for taking the time to report security issues responsibly and helping improve TUIOS.

There aren’t any published security advisories