Skip to content

Security: MuhammadLutfiMuzakiiVY/vycode

Security

SECURITY.md

Security Policy

Supported Versions

We actively provide security updates and patches for the following versions:

Version Supported
main / latest
< 1.0.0 (active dev)
legacy releases

Reporting a Vulnerability

We take the security of our projects seriously. If you believe you have found a security vulnerability in any project maintained by Muhammad Lutfi Muzaki (@MuhammadLutfiMuzakiiVY), please follow the guidelines below:

How to Submit

  • Do not disclose the vulnerability publicly in issues, pull requests, or discussions.
  • Please submit your report via GitHub Private Vulnerability Reporting on the affected repository, or email us directly.
  • Include as much information as possible:
    • Type of issue (e.g. buffer overflow, SQLi, cryptographic flaw, memory safety, token leakage)
    • Full path of source file(s) and commit hash involved
    • Step-by-step instructions or Proof of Concept (PoC) script to reproduce the issue
    • Potential impact and threat assessment

Response Timeline

  • Acknowledgment: Within 48 hours of receipt.
  • Assessment & Triage: Within 5 business days.
  • Fix & Disclosure: Coordinated disclosure after a patch is validated and deployed.

Thank you for helping keep our software and the open-source community safe!

There aren't any published security advisories