Skip to content

Latest commit

 

History

History
39 lines (25 loc) · 1.52 KB

File metadata and controls

39 lines (25 loc) · 1.52 KB

Security Policy

Supported Versions

Only the latest release of Dewy receives security updates. Please upgrade to the most recent version before reporting a vulnerability.

Version Supported
latest
< latest

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

If you believe you have found a security vulnerability in Dewy, please report it privately by sending an email to:

yo+github@tomohisaoda.com

Please include as much of the following information as possible to help us triage the report quickly:

  • A description of the issue and its potential impact
  • Steps to reproduce, including a proof of concept if available
  • The affected version(s) and environment (OS, Go version, deployment mode)
  • Any suggested mitigations or patches

You should receive an initial response within 7 days. We will work with you to understand and validate the issue, and coordinate a fix and disclosure timeline.

Disclosure Policy

We follow a coordinated disclosure process:

  1. The reporter submits a vulnerability report privately via the email above.
  2. We confirm the report and begin investigating.
  3. We develop and test a fix in a private branch.
  4. A new release is published containing the fix.
  5. A security advisory is published on GitHub, crediting the reporter unless they prefer to remain anonymous.

Thank you for helping keep Dewy and its users safe.