Skip to content

Security: NurOS-Linux/hello

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.1.x
< 2.0

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability in NurOS Hello, please report it responsibly.

How to Report

Do not open a public issue for security vulnerabilities.

Instead, please:

  1. Email: Contact the maintainers directly at anmitali198@gmail.com
  2. Telegram: Send a private message to the project maintainers

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Resolution: Depends on severity, typically within 30 days

After Reporting

  1. We will acknowledge your report
  2. We will investigate and validate the issue
  3. We will develop and test a fix
  4. We will release a security update
  5. We will publicly disclose the issue after the fix is released

Recognition

We appreciate security researchers who help keep NurOS Hello safe. With your permission, we will acknowledge your contribution in our release notes.

Security Best Practices

NurOS Hello follows these security practices:

  • No network requests without user action
  • No collection of personal data
  • Minimal permissions required
  • Regular dependency updates
  • Code review for all contributions

Scope

This security policy applies to:

Third-party forks and modifications are not covered by this policy.

There aren’t any published security advisories