This document outlines how to report security vulnerabilities in actup and what to expect during our response process.
We actively support and patch security issues in the following versions:
| Version | Supported |
|---|---|
| All versions | ✅ Yes |
Please upgrade to the latest stable release to ensure you have the latest security patches.
If you discover a security vulnerability in actup, do not open a public issue. Public disclosure puts users at risk before a patch is available.
Instead, email your report privately to me@lynicis.dev.
Please include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue, including relevant workflow files.
- Any tools or scripts required to demonstrate the exploit.
When you submit a report, here is how we handle it:
- Acknowledge: We will confirm receipt within 48 hours.
- Assess: We will verify the vulnerability and follow up if we need more details.
- Patch: We aim to develop and test a fix within 14 days.
- Publish: We will release a patched version and document the security advisory.
- Credit: We will credit your discovery in our release notes unless you request anonymity.
Thank you for helping protect actup users.