We release patches for security vulnerabilities. Which versions are eligible for receiving such patches depend on the CVSS v3.0 Rating:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability, please report it by sending an email to legal@bytebrush.dev. Please include as much information as possible to help us resolve the issue quickly.
When reporting security issues, please provide the following information:
- Component(s) affected
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Suggested mitigation or remediation steps (if any)
We will coordinate with you to handle the vulnerability responsibly. Here's what you can expect:
- Acknowledgement: We will respond to your report within 48 hours with an acknowledgement.
- Verification: We will work to verify the vulnerability and its impact.
- Remediation: We will develop a fix and test it.
- Disclosure: We will coordinate with you on the public disclosure of the vulnerability after a fix is available.
We are committed to responding quickly to security issues and will keep you informed throughout the process.