We actively support and fix security issues in the following versions of our projects:
| Version | Supported |
|---|---|
| Active | ✅ |
| Legacy | ❌ |
We take the security of our projects and users very seriously. If you believe you have found a security vulnerability, please do NOT open a public issue. Instead, report it privately to our team.
Please send an email to ksm (at) trhgquan (dot) xyz with the following details:
- Repository/Project Name: The specific project where the vulnerability exists.
- Vulnerability Type: (e.g., SQL Injection, XSS, Remote Code Execution).
- Description: A detailed description of the vulnerability.
- Steps to Reproduce: Detailed steps, code samples, or proof of concept to recreate the issue.
- Impact: What could an attacker achieve with this vulnerability?
- We will acknowledge your report and send you a round of applause (sincerely, since we don't have any money for bug bounties).
- We will work to verify the vulnerability and determine its severity.
- We will work on a fix, but please note that we don't have time to send progress updates.
- Once a fix is ready, we will apply the fix quietly without publishing any public advisories, but we will credit you privately (unless you prefer to remain completely anonymous).