Thank you for helping keep this project secure. As an open-source project, maintaining a safe environment for users is important, but resources are limited. Please review the policy below regarding supported versions and reporting vulnerabilities.
Security updates and vulnerability patches are exclusively provided for the latest Long-Term Support (LTS) release.
| Version | Supported | Notes |
|---|---|---|
| >2.0.0 (LTS) | Yes | Active support for security vulnerabilities. |
| < 2.0.0 | ❌ No | Please upgrade to the latest LTS version immediately. |
⚠️ Important: To report a valid security issue, your environment must be actively running on the latest release. Bugs or vulnerabilities found on older, modified, or deprecated branches will not be triaged.
If you discover a security vulnerability, please do not disclose it publicly via public GitHub Issues or Pull Requests.
Please follow this process instead:
- Verify: Ensure the vulnerability is reproducible on a clean install of version >2.0.0.
- Report: Send a detailed report via email to joao.coutinho08@icloud.com.
- Include Details:
- A clear description of the vulnerability.
- Steps to reproduce (or a Proof of Concept script/payload).
- The potential impact of the exploit.
You will receive an acknowledgment of your report within [48-72 hours]. If the vulnerability is verified as valid and within the scope of this project, a patch will be prepared and pushed to the main branch as a high priority.