|
| 1 | +# Security Policy |
| 2 | + |
| 3 | +## Supported Versions |
| 4 | + |
| 5 | +We actively support the following versions of `fastapi-dynamic-form` with security updates: |
| 6 | + |
| 7 | +| Version | Supported | |
| 8 | +| --------- | ------------------ | |
| 9 | +| 1.x | ✅ Fully supported | |
| 10 | + |
| 11 | +## Reporting a Vulnerability |
| 12 | + |
| 13 | +We take security issues seriously. If you find a vulnerability in `fastapi-dynamic-form`, please report it confidentially. Here are the steps to report security vulnerabilities: |
| 14 | + |
| 15 | +1. **Email**: Please send an email to [aryan513966@gmail.com](mailto:aryan513966@gmail.com) with a detailed description of the vulnerability. |
| 16 | +2. **Details**: In your email, include the following details: |
| 17 | + - Description of the vulnerability. |
| 18 | + - Potential impact and severity. |
| 19 | + - Steps to reproduce the issue. |
| 20 | + - Any other relevant information, such as proof of concept or screenshots. |
| 21 | + |
| 22 | +We will: |
| 23 | +- Acknowledge your report within 2 business days. |
| 24 | +- Work with you to understand and resolve the issue as quickly as possible. |
| 25 | +- Provide an estimate of when a patch will be available and credit you (if desired) in the changelog. |
| 26 | + |
| 27 | +## Handling Vulnerabilities |
| 28 | + |
| 29 | +When a vulnerability is confirmed: |
| 30 | +- We will create a fix and apply it to all actively supported versions of `fastapi-dynamic-form`. |
| 31 | +- A new release with the security fix will be published, and the vulnerability will be disclosed in the changelog or via a security advisory. |
| 32 | +- We may delay the disclosure of details about the vulnerability until a sufficient number of users have updated to the patched version. |
| 33 | + |
| 34 | +## General Security Guidelines |
| 35 | + |
| 36 | +- Keep your `fastapi-dynamic-form` package up to date with the latest versions to ensure you benefit from the latest security fixes. |
| 37 | +- Follow our changelog for announcements regarding security fixes. |
| 38 | +- Ensure that your configuration is secure and does not expose sensitive information. |
| 39 | + |
| 40 | +## Responsible Disclosure |
| 41 | + |
| 42 | +We strongly encourage responsible disclosure and will work to fix issues in a timely manner. We appreciate any effort to help make `fastapi-dynamic-form` more secure for all users. |
| 43 | + |
| 44 | +Thank you for helping us improve the security of `fastapi-dynamic-form`! |
0 commit comments