We release patches for security vulnerabilities in the following versions:
| Version | Supported |
|---|---|
| latest | ✅ |
| < latest | ❌ |
We take security seriously at CloudSnacks. If you discover a security vulnerability, please follow these steps:
- Open a public GitHub issue
- Disclose the vulnerability publicly before it has been addressed
- Email us: Send details to [security@cloudsnacks.io] (or create a security advisory on GitHub)
- Provide details: Include as much information as possible:
- Type of vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Wait for acknowledgment: We'll respond within 48 hours
- Acknowledgment: We'll confirm receipt within 48 hours
- Updates: We'll keep you informed about our progress
- Resolution: We'll work to address the issue promptly
- Credit: We'll acknowledge your contribution (unless you prefer to remain anonymous)
When using CloudSnacks projects:
- Keep dependencies up to date
- Use secrets management for sensitive data
- Follow principle of least privilege
- Enable audit logging
- Regularly review security configurations
- Use official releases only
We currently do not have a bug bounty program, but we deeply appreciate security researchers who help keep CloudSnacks safe.
Thank you for helping keep CloudSnacks and our users safe! 🔒