Skip to content

Security: velvet-lab/xsdk

SECURITY.md

Security Policy

Supported Versions

We actively provide security updates for the following versions of the SDK:

Version Supported
1.1.x
< 1.1.0

Reporting a Vulnerability

Please do not report security vulnerabilities via public GitHub issues.

We take the security of our SDK seriously. If you believe you have found a security vulnerability, please use one of the following private channels:

1. Private Vulnerability Reporting (Preferred)

The safest way to report a vulnerability is through GitHub's private reporting feature:

  1. Navigate to the Security tab of this repository.
  2. Select Advisories on the left sidebar.
  3. Click on Report a vulnerability.

This allows us to collaborate privately on a fix before disclosing the issue publicly.

2. Email

Alternatively, you can reach out directly via email to: danlorb@velvet-lab.net.

Our Process

  • Acknowledgement: We will acknowledge receipt of your report within 48 hours.
  • Investigation: We will investigate the issue and keep you informed of the progress.
  • Fix & Disclosure: Once a fix is ready, we will coordinate a release and a public Security Advisory (CVE), giving credit to the reporter if desired.

Thank you for helping keep velvet-lab secure!

There aren’t any published security advisories