Skip to content

Latest commit

 

History

History
48 lines (29 loc) · 1.94 KB

SECURITY.md

File metadata and controls

48 lines (29 loc) · 1.94 KB

Security Policy

Supported Versions

We release security updates only for the latest version of RxDBDotNet.

NuGet version

Note: We strongly recommend all users update to the latest version to benefit from the most recent security fixes and improvements.

Reporting a Vulnerability

If you discover a security vulnerability in RxDBDotNet, we appreciate your efforts to responsibly disclose it to us.

Please report vulnerabilities using GitHub's Private Vulnerability Reporting feature. This allows us to collaborate on resolving the issue without publicly disclosing it.

To report a vulnerability:

  1. Navigate to the RxDBDotNet repository.
  2. Click on the "Security" tab.
  3. Select "Report a vulnerability".
  4. Follow the prompts to submit your report securely.

Please include as much detail as possible to help us understand and reproduce the issue:

  • A detailed description of the vulnerability.
  • Steps to reproduce the issue.
  • Any relevant screenshots, logs, or code snippets.

Important: Do not disclose the vulnerability publicly until we have addressed it.

Response Time

  • Acknowledgment: Within 2 business days, we will acknowledge receipt of your report.
  • Investigation: We aim to investigate and respond with our findings within 7 business days.
  • Resolution: Once the vulnerability is confirmed, we will work on a fix and release it as soon as possible.

Disclosure Policy

After the vulnerability has been resolved, we will:

  • Notify you that the issue has been fixed.
  • Credit you for the discovery in our release notes, if you wish.
  • Publish a summary of the vulnerability and its impact.

Preferred Languages

We prefer to receive vulnerability reports in English.