We actively maintain and provide security updates for the latest major version of this repository:
| Version | Supported |
|---|---|
| 1.2.x | ✅ |
| 1.1.x | ✅ |
| 1.0.x | ❌ |
We take the security of our open-source software, hardware designs, and firmware drivers seriously.
If you believe you have discovered a security vulnerability or sensitive information exposure in this repository, please follow these steps:
- Do NOT open a public GitHub issue. Publicly reporting security vulnerabilities puts users and systems at risk before a patch can be deployed.
- Email your report directly to: krishnakantgarhe@gmail.com
- Include the following information in your report:
- Type of vulnerability or issue (e.g., hardcoded credentials, buffer overflow in firmware driver, workflow privilege escalation).
- Location of the affected code or configuration (file path, line number, or workflow name).
- Clear step-by-step proof of concept (PoC) or instructions to reproduce the issue.
- Any proposed remediation or patch if available.
- Acknowledgment: You will receive an initial email response acknowledging receipt of your vulnerability report within 48 hours.
- Assessment & Triage: Our maintainers will evaluate the report and confirm the vulnerability within 5 business days.
- Fix & Patch Release: A security fix will be prepared, tested, and pushed to the
mainbranch within 14 business days. - Public Disclosure: Once a security patch is deployed, a public security advisory will be published detailing the vulnerability and crediting the reporter.
Thank you for helping keep our open-source hardware, firmware, and repository security robust!