mirror of
https://github.com/Vateron-Media/XC_VM.git
synced 2026-10-04 04:02:30 +02:00
41 lines
1.4 KiB
Markdown
41 lines
1.4 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
Security fixes are provided for the latest released version of XC_VM. Please
|
|
upgrade to the most recent release before reporting an issue.
|
|
|
|
| Version | Supported |
|
|
| ------------------ | ------------------ |
|
|
| Latest release | :white_check_mark: |
|
|
| Older releases | :x: |
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
**Please do not report security vulnerabilities through public GitHub issues.**
|
|
|
|
For critical vulnerabilities (RCE, authentication bypass, privilege escalation,
|
|
data leakage), use private disclosure via **GitHub Security Advisories**:
|
|
|
|
- https://github.com/Vateron-Media/XC_VM/security/advisories/new
|
|
|
|
For lower-severity issues that are safe to disclose publicly, you may use the
|
|
[Security Vulnerability issue template](https://github.com/Vateron-Media/XC_VM/issues/new?template=security.yml).
|
|
|
|
### What to include
|
|
|
|
- A description of the vulnerability and its impact.
|
|
- Steps to reproduce (proof of concept where possible).
|
|
- Affected version / build type (MAIN or LoadBalancer) and environment.
|
|
- Any suggested remediation.
|
|
|
|
### What to expect
|
|
|
|
- **Acknowledgement** of your report within a few days.
|
|
- An initial assessment and severity classification.
|
|
- Coordinated disclosure: we will work with you on a fix timeline and credit you
|
|
in the advisory unless you prefer to remain anonymous.
|
|
|
|
Please give us a reasonable amount of time to address the issue before any public
|
|
disclosure.
|