Skip to content

Security: SergioTenza/portless-dotnet

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
4.1.x
< 4.1

Reporting a Vulnerability

We take the security of Portless.NET seriously. If you have discovered a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.

How to Report

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via one of the following methods:

  1. Email: Send a detailed report to sergio@tnzservicios.es
  2. GitHub Security Advisory: Use the GitHub Security Advisory feature to privately report a vulnerability

What to Include

Please include the following information in your report:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Affected versions (if known)
  • Potential impact of the vulnerability
  • Possible fixes (if you have suggestions)

Response Timeline

  • Acknowledgment: We will acknowledge receipt of your report within 48 hours
  • Initial Assessment: We will provide an initial assessment within 5 business days
  • Updates: We will keep you informed of our progress throughout the resolution process
  • Resolution: Critical vulnerabilities will be addressed as a priority

Responsible Disclosure

We ask that you:

  • Give us a reasonable amount of time to fix the issue before any public disclosure
  • Make a good faith effort to avoid privacy destruction, data loss, or degradation of user experience
  • Do not access or modify other users' data without permission

Recognition

We believe in recognizing the contributions of security researchers. If you report a vulnerability responsibly, we will:

  • Credit you in the security advisory (unless you prefer to remain anonymous)
  • Thank you in our release notes

Thank you for helping keep Portless.NET and its users safe!

There aren't any published security advisories