Skip to content

Security: anasyakubu/react-vite-js-starter

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of our project are currently supported with security updates. If you are using an unsupported version, please upgrade to a supported version to ensure you receive the latest security updates.

Version Supported
5.1.x
5.0.x
4.0.x
< 4.0

Reporting a Vulnerability

We take security issues seriously. If you discover a vulnerability, please follow the instructions below to report it.

How to Report

  • Email: Send an email to yakubuanas04@gmail.com with details of the vulnerability. Include as much information as possible to help us understand and address the issue quickly.
  • GitHub Issues: Do not report security vulnerabilities through public GitHub issues. Instead, use the email provided above.

What to Include

When reporting a vulnerability, please provide the following details:

  • A description of the vulnerability.
  • Steps to reproduce the issue.
  • The potential impact of the vulnerability.
  • Any suggested mitigation or fixes.

Response Time

  • We aim to acknowledge receipt of vulnerability reports within 24 hours.
  • We will provide an initial assessment and ask for any additional information if needed within 72 hours.
  • You can expect regular updates on the status of the vulnerability, typically every 5-7 days.

Resolution

  • If the vulnerability is confirmed, we will work on a fix and aim to release a patch as soon as possible.
  • Once the vulnerability is resolved, we will notify the reporter and thank them for their contribution.
  • If the vulnerability is declined, we will provide an explanation as to why it was not accepted.

Confidentiality

  • We will handle your report with strict confidentiality and will not disclose any details of the vulnerability until it has been fully addressed and a patch has been released.
  • We will not share your personal information without your permission, unless required by law.

Thank you for helping us keep our project secure.

There aren’t any published security advisories