This project actively supports and maintains the latest released version, including its dependencies, with security updates. Please ensure you are using a currently supported release to receive the latest security patches.
If you are using older versions, we strongly recommend upgrading to the latest supported version to ensure you have the latest security fixes.
The security of our users and community is a top priority. If you discover a security vulnerability in this project, please follow these steps:
-
Confidential Disclosure:
Please do not create a public GitHub issue for security vulnerabilities. Instead, email us directly at founder@rone.dev with the details. -
Information to Include:
- A clear and concise description of the vulnerability.
- Steps to reproduce the issue.
- Your environment details (version, OS, etc.).
- Any relevant logs or screenshots.
-
Response & Updates:
- We aim to acknowledge your report within 72 hours.
- You will receive updates about the investigation and any remediation plans.
- Once the vulnerability is verified and resolved, we will credit you (if you wish) and publish a security advisory.
-
Community Standards:
- Please act in good faith and avoid exploiting or sharing the vulnerability before it is resolved.
- We value and appreciate responsible disclosure to protect the entire community.
Scope, safe-harbour terms, and what is explicitly out of scope are published at https://rone.dev/security, along with machine-readable contact details at https://rone.dev/.well-known/security.txt (RFC 9116).
There is no bug bounty and no payment — this is a micro enterprise, and offering a reward we could not reliably honour would waste your time. What we can offer is a fast, human reply and public credit.
Thank you for helping keep this project and its users safe!
Maintained by RoneAI (PT RoneAI Teknologi Internasional).