Skip to content

Latest commit

 

History

History
34 lines (24 loc) · 1.25 KB

File metadata and controls

34 lines (24 loc) · 1.25 KB

Security Policy

Supported Versions

We release patches for security vulnerabilities. Which versions are eligible for receiving patches depends on the CVSS v3.0 rating:

Version Supported
Latest
< Latest

Reporting a Vulnerability

Please report security vulnerabilities to j1admin@onebyjorah.com. Do NOT report security vulnerabilities through public GitHub issues.

You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

Please include the following information:

  • Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

We prefer to receive reports via email. We will acknowledge receipt within 48 hours and send a more detailed response within 72 hours.

This project follows a 90-day disclosure timeline.