We release patches for security vulnerabilities affecting supported versions of the project. Our current policy is:
Version | Supported |
---|---|
1.0.x | ✅ |
< 1.0 | ❌ |
We take all security vulnerabilities seriously. If you discover a security issue, please report it to us privately. Do not create a public issue. Here’s how you can report a security vulnerability:
- Email us directly at: [email protected]
- Provide a detailed description of the vulnerability, including steps to reproduce it.
- Include any relevant logs or screenshots that can help in identifying and solving the issue.
- Acknowledgment: We will acknowledge the receipt of your report within 48 hours and communicate with you to understand and validate the issue.
- Assessment: We will conduct a thorough assessment of the vulnerability to determine its impact and the urgency of the fix.
- Resolution: We aim to resolve critical security issues within 7 days. After the resolution, we will issue a patch and update the affected parties.
- Disclosure: Once a fix is implemented, we will publicly disclose the nature of the vulnerability and encourage users to update to the patched version.
- Keep your software updated: Always use the latest version of
go-advanced-admin
and all its projects to ensure you have the latest security patches and improvements. - Review and Audit: Regularly review and audit the dependencies of your project for potential vulnerabilities.
- Limit Scope: Follow the principle of least privilege by limiting the scope of access and permissions of applications using this library.
We believe in responsible disclosure and will work with researchers and users to ensure vulnerabilities are patched before any details are released. We appreciate your cooperation in keeping our library secure.
If you have any questions or need further information regarding our security policy, do not hesitate to contact us at [email protected].
Thank you for helping us keep go-advanced-admin
secure.