Skip to content

Latest commit

 

History

History
24 lines (15 loc) · 1.04 KB

SECURITY.md

File metadata and controls

24 lines (15 loc) · 1.04 KB

Security Policy

Supported Versions

Version Supported
≥ 1.6.0
< 1.6.0

Reporting a Vulnerability

There are three channels for reporting security vulnerabilities:

  1. Actively exploited vulverabilities should be reported by Discord DM to '@mrogalski.eu'.
  2. Vulnerabilities that could lead to remote code execution (stack overflows, data races) should be reported through an email to "Marek Rogalski [email protected]".
  3. All other vulnerabilities (DoS, crashes) should be reported through GitHub issues.

Project is not staffed so expect response latency up to 24 hours for issues reported through Discord and up to 1 week for issues reported through email & GitHub.

In all cases a fix is always welcome.

Rolling out security updates

Gatekeeper includes built-in update mechanism which may take up to 1 week before an update takes place. It's good to avoid disseminating details of vulnerabilities during this time. Black hats may be watching!