Probe does not maintain long-term release branches. Security fixes are only included in new releases moving forward, rather than being backported to previous versions.
| Version | Supported |
|---|---|
| latest | ✅ |
| < latest | ❌ |
We take the security of Probe seriously. If you believe you've found a security vulnerability, please follow these steps:
If the vulnerability is not sensitive and does not put users at immediate risk:
- Open an Issue: Create a regular issue on our GitHub repository with the
[security]prefix in the title. - Provide Details: Include a clear description of the vulnerability, steps to reproduce, and potential impact.
- Suggest a Fix: If possible, suggest how the vulnerability might be addressed.
If the vulnerability is sensitive or could put users at immediate risk:
- Do Not Open a Public Issue: Please do not disclose sensitive vulnerabilities publicly.
- Email the Maintainers: Send an email to leonsbox@gmail.com with details about the vulnerability.
- Use Encryption: If possible, encrypt your message using our PGP key (available upon request).
- Be Patient: We'll acknowledge receipt of your report within 48 hours and provide a timeline for addressing the issue.
When reporting a vulnerability, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any potential mitigations you've identified
- Your contact information for follow-up questions
When we receive a security report, we will:
- Confirm receipt of the report within 48 hours
- Provide an initial assessment of the report within 7 days
- Keep you informed about our progress addressing the issue
- Credit you when we release a fix (unless you prefer to remain anonymous)
- Security fixes will be released as part of regular new releases
- We do not maintain or backport security fixes to previous versions
- Users are encouraged to always use the latest version of Probe
To minimize security risks when using Probe:
- Always use the latest version
- Be cautious when running Probe on untrusted codebases
- Review the permissions granted to Probe in your environment
- Follow security best practices for your operating system
Thank you for helping keep Probe and its users secure!