Skip to content

Security: udlose/MermaidPad

SECURITY.md

Security Policy

Supported Versions

This project is maintained on a best-effort basis.

  • Supported: The latest release and the main branch.
  • Unsupported: Older releases may not receive security fixes.

If you are unsure whether your version is supported, please report the issue anyway.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, use GitHub Private Vulnerability Reporting:

  1. Go to this repository’s Security tab.
  2. Select Advisories.
  3. Click Report a vulnerability and fill out the form.

You will typically receive an initial response within 7 days.

What to Include

To help triage quickly, please include:

  • Affected version(s) and OS (Windows/macOS/Linux).
  • Steps to reproduce and/or proof-of-concept code.
  • Impact assessment (what an attacker can do).
  • Any suggested fix or mitigation (if you have one).

Disclosure Policy

This project follows responsible disclosure:

  • Please allow reasonable time to investigate and patch before public disclosure.
  • If the issue is confirmed, a fix will be developed and released as soon as practical.
  • Once a fix is available, a public advisory/release notes entry may be published describing the issue and mitigation.

Security Updates

Security fixes will be released as normal GitHub Releases and documented in release notes when possible.

Non-Security Bugs

For non-security bugs and feature requests, please open a standard GitHub issue.

There aren’t any published security advisories