| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
We take the security of RuntimeEnvBundle seriously. If you believe you have found a security vulnerability, please report it privately:
- Email: security@nowo.tech (or hectorfranco@nowo.tech)
- Prefer a private GitHub security advisory when available.
- Do not open a public GitHub issue for security-sensitive bugs (secrets, encryption flaws, auth bypass).
Please include:
- Type of issue (e.g., injection, XSS, auth bypass, decryption risk, etc.)
- Affected file(s) and version/tag/commit
- Steps to reproduce
- Impact assessment
- PoC (if available)
- Initial acknowledgment: within 48 hours
- Follow-up status: within 7 days
- Resolution: depends on complexity and impact
- We confirm receipt and validate the report.
- We prepare and publish a fix as soon as possible.
- We coordinate disclosure with the reporter.
- We credit responsible disclosure (unless anonymity is requested).
See also docs/SECURITY.md.