We take the security of our project seriously. We appreciate those who help us maintain a secure environment for our community.
- All code in this repository
- Our production deployments (with proper authorization)
- Third-party dependencies (unless we're using them incorrectly)
- Beta or experimental features
- DDoS attacks
- Social engineering
- Physical infrastructure
Security updates are provided for the latest version of all packages and services currently on the main branch.
We recommend that all users and contributors stay updated to the latest commit to ensure they have the most recent security patches.
Please do not disclose security vulnerabilities through public GitHub issues.
To report a security issue, use one of the following methods:
- GitHub Security Advisory (Preferred): Submit a private security advisory
- Discord: Open a private ticket via our Discord server
- Email: Send details to mailto:naurffxiv@gmail.com
Please provide:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any proof-of-concept code (if applicable)
- Initial Response: Within 48 business hours
- Resolution Target: 90 days from initial report
Please give us time to fix the issue before disclosing it publicly.
If you find a security issue:
- Act in good faith
- Only test on accounts you own or control
- Don't access, modify, or delete user data
- Give us reasonable time to fix it before telling others
We'll work with you to resolve the issue and can credit you in our changelog if you'd like.