If you discover a security vulnerability in this project, I encourage responsible disclosure.
- Email: security@rafayhingoro.me
- Please include:
- A clear description of the issue
- Steps to reproduce (if possible)
- Potential impact and suggested fixes (if known)
Please do not open GitHub issues for security concerns. I aim to respond within 5 working days.
| Version | Status |
|---|---|
main branch |
✅ Supported |
| older tags | ❌ Not maintained |
Only the latest release or main branch is supported for security updates.
I follow a coordinated disclosure process:
- Vulnerability is reported privately.
- I investigate and confirm the issue.
- A fix is developed and released.
- (Optional) Acknowledgment is given in release notes or this file.
- Keep your dependencies up to date.
- Use tools like
govulncheckorgosecto monitor for known vulnerabilities. - This project does not have a formal bug bounty program, but I appreciate reports that help improve security.