We release patches for security vulnerabilities. Which versions are eligible for receiving such patches depends on the CVSS v3.0 Rating:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them via GitHub's security advisory feature:
- Go to https://github.com/SilentMalachite/Scriptoris/security/advisories
- Click "Report a vulnerability"
- Fill out the form with details about the vulnerability
Please include the following information:
- Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit the issue
- Initial Response: We will acknowledge receipt of your vulnerability report within 48 hours.
- Investigation: We will investigate and validate the vulnerability within 7 days.
- Resolution: We will work to resolve confirmed vulnerabilities within 30 days.
- Disclosure: We will coordinate the disclosure timeline with you.
Security updates will be released as patch versions and announced through:
- GitHub Security Advisories
- Release notes
- CHANGELOG.md
Thank you for helping keep Scriptoris secure!