We actively support the following versions of the livelyness_detection package:
| Version | Supported |
|---|---|
| 0.0.1+2 | ✅ |
| < 0.0.1+2 | ❌ |
If you discover a vulnerability in the livelyness_detection package, we greatly appreciate your efforts to report it. Please follow the guidelines below to ensure a smooth and effective resolution process:
-
Do Not Disclose Publicly: To prevent potential misuse, please do not publicly disclose the vulnerability until it has been addressed.
-
Report via Email: Send an email to security@livelyness_detection.dev with the following details:
- A description of the vulnerability.
- Steps to reproduce the issue.
- Potential impact of the vulnerability.
- Any additional information that may help us understand and resolve the issue.
-
Response Time: We aim to acknowledge receipt of your report within 48 hours and to provide an initial response within 5 business days. We will work with you to understand the issue and to develop a fix if necessary.
-
Resolution Process: Once the vulnerability is confirmed, we will take the following steps:
- Assessment: Evaluate the severity and impact of the vulnerability.
- Fix Development: Develop and test a fix for the issue.
- Release: Publish a patched version of the package on pub.dev.
- Notification: Inform users about the vulnerability and the availability of the patched version through appropriate channels (e.g., changelog, security advisories).
-
Credit: We are committed to acknowledging the contributions of security researchers. If you report a vulnerability, and it leads to a significant security improvement, we will include your name in the release notes and our Hall of Fame (unless you wish to remain anonymous).
To ensure the security of your application when using the livelyness_detection package, please follow these best practices:
- Keep Dependencies Updated: Regularly update the
livelyness_detectionpackage and other dependencies to their latest versions. - Validate Input: Always validate and sanitize input received from the camera to prevent potential injection attacks.
- Use Secure Communication: Ensure that all data transmitted between the app and any backend services is encrypted using HTTPS.
- Follow Flutter Security Guidelines: Adhere to the security guidelines provided by the Flutter framework to protect your application from common security threats.
If you have any questions or need further assistance, please contact our security team at sagar.ghag23@yahoo.com.
Thank you for helping us maintain the security and integrity of the livelyness_detection package.
This document is subject to updates. Please review it periodically for the latest information.