Skip to content

Security: laranail/enumerator

SECURITY.md

Security Policy

Where this file is silent, the laranail security policy applies.

Reporting a vulnerability

If you have discovered a security issue in laranail/enumerator, please do not open a public issue. Instead, email security@simtabi.com with:

  • A description of the vulnerability and its impact.
  • Steps to reproduce, or a proof-of-concept where applicable.
  • The package version affected.
  • Any relevant environment details (PHP version, Laravel version).

You will receive an acknowledgement within five business days. We aim to publish a fix and a CVE (where warranted) within thirty days of disclosure.

Prefer GitHub private vulnerability reporting when you can: open it from this repository's Security tab. The report arrives attached to the repo with a draft advisory and a CVE request path already in place. Email is the fallback for anyone who would rather not use GitHub.

Supported versions

Version Supported
0.1.x yes (current)

Older versions are not maintained.

Disclosure policy

We follow coordinated disclosure. Once a fix is ready and released, we will publish details of the vulnerability and credit the reporter (unless you ask to remain anonymous).

There aren't any published security advisories