Files
XC_VM/.github/SECURITY.md
T

41 lines
1.4 KiB
Markdown

# Security Policy
## Supported Versions
Security fixes are provided for the latest released version of XC_VM. Please
upgrade to the most recent release before reporting an issue.
| Version | Supported |
| ------------------ | ------------------ |
| Latest release | :white_check_mark: |
| Older releases | :x: |
## Reporting a Vulnerability
**Please do not report security vulnerabilities through public GitHub issues.**
For critical vulnerabilities (RCE, authentication bypass, privilege escalation,
data leakage), use private disclosure via **GitHub Security Advisories**:
- https://github.com/Vateron-Media/XC_VM/security/advisories/new
For lower-severity issues that are safe to disclose publicly, you may use the
[Security Vulnerability issue template](https://github.com/Vateron-Media/XC_VM/issues/new?template=security.yml).
### What to include
- A description of the vulnerability and its impact.
- Steps to reproduce (proof of concept where possible).
- Affected version / build type (MAIN or LoadBalancer) and environment.
- Any suggested remediation.
### What to expect
- **Acknowledgement** of your report within a few days.
- An initial assessment and severity classification.
- Coordinated disclosure: we will work with you on a fix timeline and credit you
in the advisory unless you prefer to remain anonymous.
Please give us a reasonable amount of time to address the issue before any public
disclosure.