This section contains information on how to report security vulnerabilities from the community or users.
To report a security vulnerability, you can follow the steps below:
- If you have found a security vulnerability, contact us here via email.
- Provide a detailed explanation of the security vulnerability.
- Include screenshots or code examples if necessary.
- The reported security vulnerability will be examined, and you will be notified whether it will be fixed or not.
- If additional information or corrections are needed during the review process, you can share that information.
- The reported security vulnerability will be addressed as quickly as possible and prioritized based on its severity.
- The security vulnerability will be tracked with regular status reports updated at specific intervals after the primary communication.
- Fixed security vulnerabilities will be released in the next version and communicated to users.
- If the reported security vulnerability is accepted, a thank-you email will be sent to the reporting party, along with the necessary recognition for their contributions.
- If a reported security vulnerability is rejected, the reasons for rejection will be explained in detail, and alternative solutions will be provided.
- The security vulnerability report and solution will be shared on the project's GitHub page with a published security update note.
- The relevant security vulnerability will not be officially disclosed until it is fixed, and information sharing will be limited during this period.
- Users and the community will be regularly informed about the reported security vulnerability on the project's GitHub page with updates.
- After fixing the security vulnerability, the project's security status will be updated, specifying the update status for supported versions.
- When a security vulnerability is detected, the components and versions affected by the vulnerability will be identified, and this information will be shared in the update note.
- All communication related to the security vulnerability will be conducted transparently, providing clarity to the community.
- User privacy and security will always be a priority during the security vulnerability reporting process.
- The status of reviewed security vulnerabilities will be regularly updated on the project's security page, accessible from the official sources of the project.
- While working on the security vulnerability report and solution, coordination with the project developers will be maintained, and the correction process will be conducted fairly and transparently.
- In response to a security vulnerability report, regular updates on the status and progress of the process will be provided to the reporting party.