The following versions of our project are currently receiving security updates:
| Version | Supported | End of Support |
|---|---|---|
| 5.1.x | ✅ | Active |
| 5.0.x | ❌ | 2024-12-31 |
| 4.0.x | ✅ | 2025-06-30 |
| < 4.0 | ❌ | 2023-12-31 |
Note: We strongly recommend using the latest stable version (5.1.x) for the best security and feature support.
We take the security of our project seriously. If you discover a security vulnerability, please report it responsibly by following these guidelines:
- DO NOT create a public GitHub issue for security vulnerabilities
- Email your findings to the404studios@gmail.com
- Include the following information:
- Type of vulnerability
- Full paths of source file(s) related to the vulnerability
- Location of the affected source code (tag/branch/commit or direct URL)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
- Initial Response: Within 48 hours
- Status Update: Within 5 business days
- Resolution Timeline: Depends on severity
- Critical: 7-14 days
- High: 14-30 days
- Medium: 30-60 days
- Low: 60-90 days
After reporting a vulnerability:
- You'll receive an acknowledgment of your report
- We'll investigate and validate the issue
- We'll work on a fix and coordinate a release
- We'll publicly acknowledge your contribution (unless you prefer to remain anonymous)
Security advisories will be published through:
- GitHub Security Advisories
- Our mailing list
- Project blog/website
When contributing to this project, please follow these security best practices:
- Dependencies: Keep all dependencies up to date
- Secrets: Never commit secrets, credentials, or API keys
- Input Validation: Always validate and sanitize user input
- Authentication: Use strong authentication mechanisms
- Encryption: Use encryption for sensitive data in transit and at rest
- We follow a coordinated disclosure policy
- Security issues will be disclosed publicly after patches are available
- We aim to disclose vulnerabilities within 90 days of the initial report
- Credit will be given to security researchers who report valid issues
If you have suggestions for improving this policy, please submit a pull request or open an issue for discussion.