Skip to content

Security: HeapReaper/Kiyomi

SECURITY.MD

Security Policy

Supported Versions

We actively support the following versions of our project. Please ensure you're using one of these versions to receive updates and security patches.

Version Supported
1.x [✓]
0.x [✗]

Reporting a Vulnerability

We take security issues seriously. If you discover a vulnerability, please follow these steps to report it:

  1. Contact Us: Email us at [email protected] with a detailed description of the vulnerability.
  2. Provide Details: Include steps to reproduce the issue, potential impact, and any suggestions for remediation if possible.
  3. Confidentiality: Do not disclose the vulnerability publicly until we have resolved it and provided a patch.

We aim to acknowledge all reports within 48 hours and resolve critical issues within 14 days.

Scope

This security policy covers the following areas:

  • Vulnerabilities in the project’s codebase.
  • Issues with dependencies explicitly included in the project.
  • Misconfigurations in deployment examples provided by us.

Exclusions

We do not handle:

  • Issues with third-party services or integrations not maintained by us.
  • End-user device security issues.

Thank You

We value and appreciate the effort of security researchers and community members who help us maintain the safety and reliability of our project.

There aren’t any published security advisories