Skip to content

Security: emreisik95/eksilik-os

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest code on main and released in the next available TestFlight or App Store build. Older builds are not maintained separately.

Report a vulnerability privately

Use GitHub's private vulnerability reporting flow: Report a vulnerability.

Please include:

  • the affected version or commit;
  • a clear description of the impact;
  • minimal reproduction steps or a proof of concept;
  • any suggested mitigation;
  • whether the issue is already public.

Do not open a public issue for a suspected vulnerability. Do not include real passwords, session cookies, private messages, signing certificates, provisioning profiles, or personal data in a report. Use a disposable test account and redact identifiers whenever possible.

The maintainer will aim to acknowledge a report within seven days, keep the reporter informed while it is investigated, and coordinate disclosure after a fix is available. Please allow a reasonable remediation window before publishing details.

Scope

Security issues in the app, its local storage, authentication handling, deep links, widgets, build pipeline, or dependency chain are in scope. Vulnerabilities in Ekşi Sözlük itself should be reported directly to that service because this project does not operate its servers.

There aren't any published security advisories