mirror of
https://github.com/chuot/rdio-scanner.git
synced 2026-08-13 08:33:00 -06:00
56 lines
1.5 KiB
Markdown
56 lines
1.5 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
Security updates are provided for the latest version of **rdio-scanner**.
|
|
Older versions may not receive patches unless the issue is critical.
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
If you discover a security vulnerability, we appreciate your help in responsibly disclosing it.
|
|
|
|
**Please do NOT open a public GitHub issue.**
|
|
|
|
Instead, contact us privately at: **<rdio-scanner@saubeo.solutions>**
|
|
|
|
Include as much detail as possible:
|
|
|
|
- Steps to reproduce
|
|
- Impact assessment
|
|
- Affected versions
|
|
- Any proof-of-concept code (if applicable)
|
|
|
|
We will acknowledge your report within **72 hours**.
|
|
|
|
## Disclosure Process
|
|
|
|
1. We investigate the report and confirm the vulnerability.
|
|
2. We work with you (if needed) to understand the issue fully.
|
|
3. We prepare a fix and coordinate a release.
|
|
4. We publish a security advisory once the fix is available.
|
|
|
|
We aim to resolve validated security issues within **14 days**, depending on severity and complexity.
|
|
|
|
## Scope
|
|
|
|
This policy applies to:
|
|
|
|
- The rdio-scanner codebase
|
|
- Documentation
|
|
- Any related scripts or tooling included in the repository
|
|
|
|
It does **not** cover:
|
|
|
|
- Third-party dependencies
|
|
- External services or infrastructure not maintained by Saubeo Solutions
|
|
|
|
## Responsible Disclosure
|
|
|
|
We ask that you:
|
|
|
|
- Give us reasonable time to fix the issue before public disclosure
|
|
- Avoid actions that could harm users or data
|
|
- Follow ethical security research practices
|
|
|
|
We greatly appreciate your contribution to the safety and reliability of rdio-scanner.
|