We actively provide security updates and patches for the following versions:
| Version | Supported |
|---|---|
main / latest |
✅ |
< 1.0.0 (active dev) |
✅ |
| legacy releases | ❌ |
We take the security of our projects seriously. If you believe you have found a security vulnerability in any project maintained by Muhammad Lutfi Muzaki (@MuhammadLutfiMuzakiiVY), please follow the guidelines below:
- Do not disclose the vulnerability publicly in issues, pull requests, or discussions.
- Please submit your report via GitHub Private Vulnerability Reporting on the affected repository, or email us directly.
- Include as much information as possible:
- Type of issue (e.g. buffer overflow, SQLi, cryptographic flaw, memory safety, token leakage)
- Full path of source file(s) and commit hash involved
- Step-by-step instructions or Proof of Concept (PoC) script to reproduce the issue
- Potential impact and threat assessment
- Acknowledgment: Within 48 hours of receipt.
- Assessment & Triage: Within 5 business days.
- Fix & Disclosure: Coordinated disclosure after a patch is validated and deployed.
Thank you for helping keep our software and the open-source community safe!