Version | Supported |
---|---|
Latest | ✅ |
We take the security of Legion seriously. If you believe you have found a security vulnerability, please report it to us as described below.
Please do not report security vulnerabilities through public GitHub issues.
Instead:
- Email us at [email protected]
- Include as much information as possible:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Versions affected
- Potential impact
- Suggested fixes (if any)
After you submit a report:
- You'll receive an acknowledgment within 48 hours.
- We'll investigate and keep you updated on our findings.
- Once we've determined the impact and resolution:
- We'll develop and test a fix
- We'll establish a disclosure timeline
- We'll notify affected users as appropriate
We support safe harbor for security research that:
- Follows our reporting guidelines
- Makes a good faith effort to avoid privacy violations, data destruction, service interruption, and other harm
- Does not exploit findings beyond what's necessary to demonstrate the vulnerability
We aim to address critical vulnerabilities within 30 days. We request that you keep vulnerabilities private until we release fixes. We'll coordinate with you on a disclosure timeline that serves both the community's need to update and your recognition as the reporter.
-
Dependency Management
- Keep dependencies up to date
- Review dependency changes carefully
- Use dependabot alerts
-
Code Review
- Review for security implications
- Follow secure coding guidelines
- Use security linters when possible
-
Secrets and Credentials
- Never commit secrets or credentials
- Use environment variables for sensitive data
- Review code for accidental credential exposure
Security updates will be released as:
- Immediate patches for critical vulnerabilities
- Regular updates for non-critical security improvements
- Dependencies updates via automated tools
Updates will be announced through:
- GitHub Security Advisories
- Release notes
- Discord announcements channel
If you have questions about this policy or Legion's security practices, please reach out on our Discord server in the #help channel.