Skip to content

Latest commit

 

History

History
63 lines (39 loc) · 1.81 KB

File metadata and controls

63 lines (39 loc) · 1.81 KB

Security Policy

Overview

We take the security of our project seriously. We appreciate those who help us maintain a secure environment for our community.

Scope

In Scope

  • All code in this repository
  • Our production deployments (with proper authorization)

Out of Scope

  • Third-party dependencies (unless we're using them incorrectly)
  • Beta or experimental features
  • DDoS attacks
  • Social engineering
  • Physical infrastructure

Supported Versions

Security updates are provided for the latest version of all packages and services currently on the main branch.

We recommend that all users and contributors stay updated to the latest commit to ensure they have the most recent security patches.

Reporting a Vulnerability

Please do not disclose security vulnerabilities through public GitHub issues.

To report a security issue, use one of the following methods:

  1. GitHub Security Advisory (Preferred): Submit a private security advisory
  2. Discord: Open a private ticket via our Discord server
  3. Email: Send details to mailto:naurffxiv@gmail.com

What to Include

Please provide:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any proof-of-concept code (if applicable)

What Happens Next

  • Initial Response: Within 48 business hours
  • Resolution Target: 90 days from initial report

Please give us time to fix the issue before disclosing it publicly.

Guidelines

If you find a security issue:

  • Act in good faith
  • Only test on accounts you own or control
  • Don't access, modify, or delete user data
  • Give us reasonable time to fix it before telling others

We'll work with you to resolve the issue and can credit you in our changelog if you'd like.