Skip to content

Security: mmqnym/quickcerts

SECURITY.md

Security Policy

Supported Versions

Below is a table of versions of my project. Please note that only the versions marked as supported will receive security updates.

Version Supported
>= 1.0.4
<= 1.0.3

Reporting a Security Vulnerability

I am truly grateful for your help in identifying and reporting security vulnerabilities. Your efforts in responsibly disclosing these issues are immensely valuable to me. If you discover a security vulnerability, I kindly ask you to follow these steps:

  • Please avoid disclosing the issue publicly, such as in GitHub issues or public discussions.
  • Contact me directly via email (HERE) with details of the vulnerability.
  • If possible, include steps to reproduce the vulnerability. This information can significantly expedite my understanding and resolution of the problem.
  • Rest assured, I will respond to your report as swiftly as possible and keep you updated as I address the issue.

Handling Process

Upon receipt of a security vulnerability report, I will handle it with utmost care, following this process:

  1. Acknowledge receipt of your report and initiate communication.
  2. Investigate the issue to understand which versions are affected.
  3. Develop necessary fixes and release them in the latest version.
  4. Release updates and disclose the issue publicly, extending my sincere thanks to you for your contribution.

Public Disclosure Timeline

My goal is to address and publicly disclose the issue within 60 days of receiving a report. However, this timeline might vary depending on the complexity of the issue and the extent of necessary remedial actions.

Acknowledgements and Recognition

For those who assist in enhancing the security of this project, I will acknowledge your contributions in the documentation, expressing my gratitude for your invaluable support.


I sincerely thank you for your assistance in maintaining the security and integrity of this project. Your contributions are deeply appreciated.

There aren’t any published security advisories