We take the security of applecontainer-go seriously. This document outlines our policy for reporting and handling security vulnerabilities.
Currently, security updates and patches are provided for the following versions:
| Version | Supported |
|---|---|
| v0.x / Main branch | ✅ |
| < v0.1.0 | ❌ |
If you discover a security vulnerability in this project, please do not open a public issue. Instead, report it using one of the following methods:
- GitHub Private Vulnerability Report: Please use the "Report a vulnerability" button under the Security tab on GitHub.
- Email: Send a detailed email to me@lynicis.dev.
To help us investigate and address the vulnerability quickly, please include:
- A description of the issue and the potential impact.
- Step-by-step instructions or a minimal proof-of-concept (such as a Go test case) to reproduce the behavior.
- Any details about the environment or configurations where it was observed.
- Acknowledgement: We will acknowledge receipt of your vulnerability report within 48 hours.
- Investigation & Fix: We will investigate the issue and, if confirmed, work on a fix/patch. We may contact you for further details or to test the proposed fix.
- Disclosure: Once the fix is ready, we will coordinate the release of a security advisory and a patched version. We request that you do not disclose the vulnerability publicly until a patch is released and we have coordinated disclosure.