We take security seriously. If you discover a vulnerability in our project, please report it to us responsibly.
Please do not create a public GitHub issue. Instead, please email ahmed.moussa@compubotics.tech with the details of the vulnerability.
Please include the following information in your report:
- Description of the vulnerability: Provide a clear and concise description of the vulnerability.
- Steps to reproduce: Include detailed steps on how to reproduce the vulnerability.
- Impact of the vulnerability: Explain the potential impact of the vulnerability if exploited.
- Suggested fix (if applicable): If you have a suggestion for how to fix the vulnerability, please include it in your report.
We will acknowledge receipt of your report within two (2) business days and keep you informed of the progress of our investigation and remediation efforts.
We currently support the following versions of our project:
- Only Latest Version of the Project.
We encourage users to update to the latest supported version to ensure they have the latest security fixes.
When a security vulnerability is reported, we will:
- Acknowledge receipt of the report and begin our investigation.
- Assess the severity of the vulnerability.
- Develop a fix for the vulnerability.
- Release a new version of the project with the fix.
- Publicly disclose the vulnerability after a fix is available.
We may also release security advisories or updates to inform users of vulnerabilities and provide guidance on mitigation strategies.
We follow security best practices in the development and maintenance of our project, including:
- Code review: All code changes are reviewed by at least one other developer before being merged.
- Automated testing: We use automated tests to ensure the quality and security of our code.
- Dependency management: We use dependency management tools to track and update our project's dependencies.
- Security audits: We may conduct periodic security audits to identify and address potential vulnerabilities.
If you have any questions or concerns about security, please contact us at ahmed.moussa@compubotics.tech.