This document outlines how to report vulnerabilities. Td is a personal open-source project maintained in free time, without funding for security bounties or rewards.
If you discover a security vulnerability in Td, please follow these steps:
- Do Not create a public GitHub issue
- Email your findings to td+security@thelazysre.com or use GitHub's private security vulnerability reporting feature
- Include:
- A brief description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if you have one)
- Initial Response: You'll receive an acknowledgment within 72 hours
- Updates: We'll keep you informed about the progress every 7 days
- Resolution: Once resolved, we'll notify you
While we deeply appreciate security reports, please note that as a personal project, we cannot offer monetary compensation or bounties for vulnerability reports.
- If accepted: We'll work on a fix and coordinate the release with you
- If declined: We'll explain why and work with you if clarification is needed
- Keep your dependencies up to date
- Use the latest stable version of Td
- Follow security best practices in your implementation
- Enable GitHub's automated security updates
Thank you for helping keep Td and its community secure! 🔒