Skip to content

Security: NIKX-Tech/relayly

Security

SECURITY.md

Security Policy

Supported Versions

Relayly is currently in active development. We support security updates for the following versions:

Version Supported
v0.x
< v0.x

Reporting a Vulnerability

We take the security of Relayly seriously. If you discover a security vulnerability, please do not disclose it publicly.

How to Report

  1. GitHub Private Vulnerability Reporting: The preferred way to report a vulnerability is through GitHub's Private Vulnerability Reporting feature on this repository.
  2. Email: Alternatively, you can send an email to tech@nikx.one.

What to Expect

  • Acknowledgment: You will receive an acknowledgment of your report within 48 hours.
  • Updates: We will provide regular updates on the status of the vulnerability until it is resolved.
  • Disclosure: Once a fix is verified, we will coordinate a public disclosure date with you. We prefer to release a security advisory via GitHub Advisories.

Response Process

  1. Assessment: We will evaluate the report to determine the severity and impact.
  2. Acceptance/Decline: We will notify you if the vulnerability is accepted or declined. If declined, we will provide a clear explanation.
  3. Remediation: If accepted, we will work on a fix in a private fork.
  4. Validation: We may ask you to verify the fix if possible.
  5. Release: We will release a new version of Relayly containing the fix.

There aren't any published security advisories