We release patches for security vulnerabilities. Which versions are eligible for receiving such patches depends on the CVSS v3.0 Rating:
| Version | Supported |
|---|---|
| 1.1.x | ✅ |
| 1.0.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in rtl-text-tools, please report it privately so we can address it before it is publicly disclosed.
Please do not open a public GitHub issue for security vulnerabilities.
Please email homayoun763@gmail.com with the details of the vulnerability.
When reporting, please include as much of the following information as possible to help us understand and resolve the issue:
- A clear description of the vulnerability.
- Steps to reproduce the issue (if applicable).
- The potential impact of the vulnerability.
- Any suggested fixes or mitigations (if you have them).
- Acknowledgment: We will acknowledge receipt of your report within 48 hours.
- Assessment: We will evaluate the vulnerability and determine its severity and impact on the package.
- Resolution: We will work on a fix and release a patch as quickly as possible.
- Disclosure: We will coordinate with you on the public disclosure timeline. We generally aim to disclose vulnerabilities publicly 90 days after they are reported, or sooner if a fix is released.
Thank you for helping keep rtl-text-tools and its users safe!