krz/domain-dig

an ios app for DNS & SSL analysis

clone: git clone https://gitbay.org/krz/domain-dig.git

v4.4.1: SECURITY.md · raw

 1# Security Policy
 2
 3## Supported Versions
 4
 5|Version|Supported|
 6|-------|---------|
 7| 1.x   | ✅ Yes  |
 8| < 1.0 | ❌ No   |
 9
10---
11
12## Reporting a Vulnerability
13
14If you discover a security vulnerability, **do not open a public issue**.
15Instead:
16
171. **Email** your report to [security@cleberg.net](mailto:security@cleberg.net).
18  Include:
19  - A detailed description of the vulnerability
20  - Steps to reproduce
21  - Any relevant context (e.g., affected versions, environment)
222. **Response Time**: We will acknowledge your report within **3 business days**
23  and keep you updated on the progress.
243. **Resolution**: If confirmed, we will:
25  - Provide an estimated timeline for a fix
26  - Work with you to verify the resolution
27  - Credit you for the discovery (if you wish)
284. **Declined Reports**: If the report is invalid or out of scope, we will
29  explain why and close the issue.
30
31---
32
33**Thank you for helping improve the security of our project!**