We release security patches and updates for actively maintained versions. The table below outlines supported versions:
| Version | Supported |
|---|---|
| Latest | ✅ |
| < Latest | ❌ |
If you discover a potential security vulnerability in this project, please report it responsibly and privately.
Please do not disclose security vulnerabilities through public GitHub issues, discussions, or pull requests.
- GitHub Private Vulnerability Reporting: Submit a confidential advisory directly via GitHub Security Advisories.
- Email: Send a confidential email to the LF Decentralized Trust security
team:
- Recipient: security@lists.lfdecentralizedtrust.org
- Subject:
[SECURITY] eudiplo: <brief description>
To help us triage and resolve the report quickly, please include as much detail as possible:
- Type and severity of the vulnerability (for example, authentication bypass, injection, cryptographic flaw, or credential disclosure)
- Affected package, application, and version(s)
- Location of the affected code (tag, branch, commit, or direct file link)
- Clear step-by-step instructions to reproduce the issue
- Minimal proof-of-concept code or sample inputs, when appropriate
- Potential impact and exploitation scenarios
- Any suggested fixes or mitigations
- Your contact information, if you would like follow-up
- Initial Acknowledgment: Within 3 business days of receipt
- Triage and Assessment: Within 10 business days, including preliminary severity assessment and reproduction verification
- Regular Updates: We will keep you informed of our progress as remediation proceeds
- Remediation and Patch: Fix development and testing will be prioritized based on severity
- Coordinated Disclosure: Fixes will be released alongside a published GitHub security advisory and CVE identifier, where applicable
- Triage: We evaluate the severity and impact of the reported vulnerability
- Investigation: Our team investigates and confirms the vulnerability
- Fix Development: We develop and test a fix in private, when appropriate
- Release: We release a security update
- Advisory Publication: We publish a GitHub security advisory with impact, affected versions, and mitigation or upgrade steps
- Disclosure: We coordinate responsible disclosure with the reporter
When using this project, we recommend:
- Keep dependencies up to date
- Use the latest stable version
- Follow secure coding practices
- Regularly review security advisories
- Implement proper authentication and authorization
- Use HTTPS in production environments
- Regularly backup your data
This security policy applies to:
- The main codebase in this repository
- Dependencies we directly maintain
- Documentation and configuration examples
This policy does not cover:
- Third-party dependencies (please report to their respective maintainers)
- Issues in forked repositories
- Social engineering attacks
We believe in recognizing security researchers who help us maintain the security of our project. With your permission, we will:
- Credit you in our security advisory
- Add you to our security acknowledgments
- Mention you in release notes (if desired)
For security-related questions or concerns, please contact:
- Preferred Contact: GitHub Security Advisories
- Security Email: security@lists.lfdecentralizedtrust.org
- Response Time: Within 3 business days
Thank you for helping keep our project and community safe!