We actively support the following versions of Laler with security updates:
| Version | Supported |
|---|---|
| >= 1.0 | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in Laler, please help us maintain the security of the project by reporting it responsibly.
- DO NOT create a public issue on GitHub
- DO NOT discuss the vulnerability in public forums or chat rooms
- DO send an email to: mahatmamahardhika200588@gmail.com
Please include the following information in your report:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any suggested fixes or mitigations
- Your contact information for follow-up questions
- Initial Response: We will acknowledge receipt of your report within 48 hours
- Assessment: We will assess the vulnerability within 5 business days
- Resolution: Critical vulnerabilities will be addressed within 7 days, others within 30 days
- Disclosure: We will coordinate responsible disclosure with you
We are committed to working with security researchers to verify and address any potential vulnerabilities. We ask that you:
- Give us reasonable time to investigate and fix the issue before public disclosure
- Avoid accessing, modifying, or deleting data that doesn't belong to you
- Don't perform actions that could harm the reliability or integrity of our services
When using Laler in production:
- Keep Updated: Always use the latest stable version
- Network Security: Ensure TauriDumper endpoints are not exposed to untrusted networks
- Access Control: Limit access to debug interfaces in production environments
- Data Sensitivity: Be careful not to dump sensitive information (passwords, API keys, etc.)
We appreciate the security research community's efforts to improve the safety of open source software. Researchers who responsibly disclose vulnerabilities will be acknowledged in our security advisories (with their permission).
For any security-related questions or concerns, please contact:
- Email: mahatmamahardhika200588@gmail.com
- GitHub: @programinglive
This security policy is effective as of October 2025 and may be updated as needed.