Skip to content

Security: 2MJ-DEV/243DRC

Security

SECURITY.md

Security Policy

Supported Versions

This section lists the versions of the platform that are currently supported with security updates.

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability, please follow the responsible disclosure process described below.

Where to report

  • Email (primary and confidential): julesmukadi.dev@gmail.com
  • GitHub Issues: Only for non‑critical vulnerabilities (without exploit details)

What to include in your report

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (optional but appreciated)

Response timeline

  • Acknowledgement of receipt: within 48 hours
  • Initial assessment update: within 3–7 days
  • Status updates: at least once per week until resolved

What happens next

If the issue is accepted:

  • We work with the maintainer if it concerns a open‑source project
  • The vulnerability remains confidential until patched
  • You may receive recognition in our security contributors section (if you wish)

If the issue is declined:

  • You will receive a detailed explanation
  • We will inform you if the report was out of scope or not reproducible

What NOT to do

  • Do not publicly disclose the vulnerability
  • Do not attempt to exploit or access user/project data
  • Do not perform attacks, scans, or automated testing without authorization

⚠ Violations may lead to ban and legal actions under applicable national and international laws.

There aren’t any published security advisories