Skip to content

Security: Itszavier/fluidauth-express

SECURITY.md

Security Policy

Supported Versions

This section lists the versions of our project that are actively supported with security updates.

Version Supported
1.x.x

The latest version of FluidAuth includes security updates.

Reporting a Vulnerability

To report a security vulnerability, please use the following methods:

  1. GitHub Issues:

    • Submit your report through GitHub Issues in the repository issues tracker.
    • Include a detailed description of the vulnerability, steps to reproduce, and any potential impact.
  2. GitHub Discussions:

    • Alternatively, you can use GitHub Discussions to report and discuss potential security issues in our discussions page.
  3. Response Time:

    • You will receive an acknowledgment of your report within 48 hours.
    • We will provide regular updates on the status of the report, typically every 7 days.
  4. Evaluation:

    • Our security team will evaluate the report and determine its validity.
    • If the vulnerability is accepted, we will work on a fix and provide a timeline for its release.
    • If the vulnerability is declined, we will inform you of the reasons and any alternative recommendations.
  5. Disclosure:

    • We follow a coordinated disclosure process.
    • Details of accepted vulnerabilities will be published in our release notes and/or security advisories after the fix is deployed.
  6. Thank You:

    • We appreciate the efforts of individuals who help us improve our security.
    • Contributors who identify valid vulnerabilities may be acknowledged in our release notes or receive other forms of recognition.

There aren’t any published security advisories