Skip to content

Security: prince-chhirolya/Docusaurus-AIOR

SECURITY.md

Security Policy

1. Supported Versions

We take security seriously and aim to provide prompt fixes for vulnerabilities. Below are the versions of this project currently supported with security updates:

Version Supported
1.x
< 1.0

Please ensure you’re using a supported version to receive security updates.


2. Reporting a Vulnerability

If you discover a security vulnerability, we encourage you to report it to us responsibly.

2.1. How to Report

  • Email: Please send an email to chhirolyaprince@gmail.com with details of the vulnerability.
  • GitHub Issues: Avoid publicly disclosing security issues in GitHub Issues. Instead, use email for initial contact.

2.2. Information to Include

When reporting a vulnerability, please provide:

  • A detailed description of the issue and potential impact.
  • Steps to reproduce the vulnerability.
  • Any relevant code snippets, logs, or screenshots.
  • Your contact information for follow-up questions.

2.3. Response Timeline

We aim to:

  1. Respond to vulnerability reports within 3 business days.
  2. Investigate and confirm the issue within 7 business days.
  3. Release a patch within 14 business days if the issue is confirmed.

You’ll receive updates on the status of the investigation and resolution.


3. Vulnerability Disclosure Policy

To protect our users, we ask that you:

  • Privately report vulnerabilities: Give us the opportunity to address the issue before making it public.
  • Wait for a patch: Allow us time to develop and release a fix before disclosing the vulnerability.

Our goal is to work with the community to keep our project secure for all users.


4. Security Updates and Alerts

For major security updates, we will:

  • Post an advisory on the GitHub repository.
  • Notify users by tagging a release that includes the fix.

5. Thank You

We appreciate responsible disclosure and will acknowledge individuals who report security issues responsibly in our release notes. Thank you for helping us keep this project safe!


There aren’t any published security advisories