| Version | Supported |
|---|---|
| 2.1.x | ✅ |
| 2.0.x | ✅ |
| 1.x.x | ❌ |
If you discover a security vulnerability within hurstify, please send an email to the maintainers via GitHub Issues. All security vulnerabilities will be promptly addressed.
Please do NOT report security vulnerabilities through public GitHub issues.
When reporting a vulnerability, please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- The version(s) of hurstify affected
- Any potential mitigations you have identified
- Acknowledgment: We will acknowledge receipt of your report within 48 hours.
- Assessment: We will investigate and validate the report within 7 business days.
- Resolution: We will work on a fix and coordinate disclosure with you.
- Disclosure: We will publish a security advisory once the fix is released.
- We request that you give us a reasonable amount of time to address the issue before public disclosure.
- We will credit reporters in the security advisory unless they prefer to remain anonymous.
- We will not take legal action against researchers who report vulnerabilities in good faith.
- Always use the latest version of hurstify.
- Review the CHANGELOG.md for security-related updates.
- When using RK-SAVR in production, ensure your environment is properly secured.
- Do not expose internal endpoints or debugging interfaces in production.
We use Dependabot to keep dependencies up to date. Security patches are applied promptly.
For any security concerns, please open a private issue or contact the maintainers directly.