| Version | Supported |
|---|---|
| v2.x | ✅ Active development |
| v1.x | ❌ No longer supported |
If you discover a security vulnerability in Friday, please report it privately.
Do not open a public issue. Instead, send a direct message to alimaandev on GitHub or email the project maintainer (available via the GitHub profile).
You should receive a response within 48 hours. If you don't, follow up with a public issue tagged security (without sensitive details).
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fix (optional)
- 48 hours — Initial acknowledgment
- 7 days — Status update
- 30 days — Target resolution for confirmed vulnerabilities
This policy covers the Friday codebase hosted at https://github.com/alimaandev/Friday. It does not cover third-party dependencies — report those to their respective maintainers.
English, please.