Use this section to tell people about which versions of your project are currently being supported with security updates.
| Version | Supported |
|---|---|
| v1.0.x | ✅ |
| < 1.0 | ❌ |
We take the security of FairMind very seriously. If you have discovered a security vulnerability in FairMind, please report it to us as described below.
Please do not report security vulnerabilities through public GitHub issues.
Please email us at security@fairmind.xyz with a description of the vulnerability. We encourage you to use [PGP] to encrypt your communications with us.
Please include the following details in your report:
- The type of vulnerability (e.g., XSS, SQLi, RCE)
- Full paths to source file(s) related to the manifestation of the vulnerability
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the vulnerability, including how an attacker might exploit it
We will acknowledge receipt of your report within 24 hours. We will then work with you to understand and resolve the issue.
We ask that you give us a reasonable amount of time to fix the vulnerability before disclosing it to the public. We will notify you when the vulnerability is fixed and when it is safe to disclose.