| Version | Supported |
|---|---|
| 0.x | ✅ |
If you discover a security vulnerability in ActionGuard, please report it responsibly.
Do NOT open a public issue.
Instead, email us at: security@actionguard.dev
We will acknowledge receipt within 48 hours and provide a detailed response within 5 business days.
- We will confirm the vulnerability and determine its impact.
- We will release a fix as soon as possible.
- We will credit the reporter (unless they prefer to remain anonymous).
When using ActionGuard:
- Always keep ActionGuard updated to the latest version.
- Never commit
.envfiles or API keys to your repository. - Use the CSRF middleware for state-changing actions.
- Enable audit logging for sensitive operations.
- Use rate limiting to prevent abuse.