Skip to content

Security: manucian-official/Devpulse-tool

SECURITY.md

Security Policy

Supported Versions

The following table indicates which versions of this project currently receive security updates and maintenance. Only versions marked as supported will receive patches for newly discovered security vulnerabilities.

Version Supported
v1.0.0 ✅ Supported
v0.2.1 ❌ Not supported
v0.2.0 ✅ Supported
< 0.2.0 ❌ Not supported

Support Policy

  • The latest stable version is always prioritized for security fixes and updates.
  • Older supported versions may receive limited security patches depending on the severity of the vulnerability.
  • Versions that are End-of-Life (EOL) will not receive any security updates. Users are strongly encouraged to upgrade to a supported version.

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly so that it can be fixed as quickly as possible.

How to Report

Please report vulnerabilities through one of the following methods:

  • Open a private security advisory on GitHub.
  • Email the maintainers at: khoigaming2102pro@gmail.com
  • If available, submit a report through the project's security issue template.

When reporting a vulnerability, please include as much detail as possible:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • A proof of concept (if available)
  • The affected version(s)
  • Potential impact of the vulnerability

Response Timeline

After a vulnerability is reported:

  1. Acknowledgment:
    We will confirm receipt of the report within 48 hours.

  2. Investigation:
    The maintainers will review and validate the vulnerability.

  3. Resolution:
    If confirmed, we will work on a patch and release a fix in a supported version.

  4. Disclosure:
    Once a fix is available, we may publish a security advisory describing the vulnerability and the mitigation steps.

Responsible Disclosure

Please do not publicly disclose the vulnerability until a fix has been released. This helps protect users who may still be running vulnerable versions.

If the Vulnerability Is Not Accepted

If the reported issue is determined not to be a security vulnerability, we will explain the reasoning and may redirect it to the normal issue tracker.


Security Best Practices

Users are encouraged to follow these best practices:

  • Always use the latest supported version of the software.
  • Keep dependencies updated regularly.
  • Avoid running outdated versions in production environments.
  • Monitor security advisories related to this project.

Thank you for helping improve the security of this project.

There aren’t any published security advisories