Where this file is silent, the laranail security policy applies.
If you have discovered a security issue in laranail/enumerator, please
do not open a public issue. Instead, email security@simtabi.com
with:
- A description of the vulnerability and its impact.
- Steps to reproduce, or a proof-of-concept where applicable.
- The package version affected.
- Any relevant environment details (PHP version, Laravel version).
You will receive an acknowledgement within five business days. We aim to publish a fix and a CVE (where warranted) within thirty days of disclosure.
Prefer GitHub private vulnerability reporting when you can: open it from this repository's Security tab. The report arrives attached to the repo with a draft advisory and a CVE request path already in place. Email is the fallback for anyone who would rather not use GitHub.
| Version | Supported |
|---|---|
| 0.1.x | yes (current) |
Older versions are not maintained.
We follow coordinated disclosure. Once a fix is ready and released, we will publish details of the vulnerability and credit the reporter (unless you ask to remain anonymous).