We actively support the latest release of each public DevToolie project. Older versions may not receive security fixes.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Prior major | Case-by-case |
Unreleased / main |
Best-effort |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, email siddharthmehta0906@gmail.com with:
- A clear description of the vulnerability
- Steps to reproduce (PoC if possible)
- Impact assessment (what an attacker could achieve)
- Affected repository / package / version
- Any suggested remediation
If the repository has GitHub private vulnerability reporting enabled, you may also use that.
| Step | Target |
|---|---|
| Acknowledgement | within 3 business days |
| Initial assessment | within 7 business days |
| Fix / advisory timeline | communicated after triage |
We will keep you informed of progress and credit you in any advisory (unless you prefer to remain anonymous).
We consider good-faith security research conducted within this policy to be authorized. We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, and service interruption
- Do not access or modify data beyond what is needed to demonstrate the issue
- Report findings promptly and privately
- Give us reasonable time to remediate before public disclosure
Please do not publicly disclose the issue until we have shipped a fix or agreed on a coordinated disclosure date.