Security updates are applied only to the latest stable release of v-serpbear.
Older versions may not receive patches. Users are encouraged to upgrade to the latest release.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
If you discover a security issue, please do not open a public GitHub issue.
Instead, report it responsibly:
- Email: contact@vontainment.com
- Include:
- A description of the issue.
- Steps to reproduce (if possible).
- The potential impact.
- Suggested fixes (optional).
You will receive an acknowledgment within 72 hours.
We aim to provide a fix or mitigation within 14 days, depending on severity.
- Dependencies are reviewed and updated regularly.
- Automated scans and code reviews help prevent common vulnerabilities.
- Sensitive data (e.g., API keys, passwords) should never be committed to the repository.
- Pull requests introducing new dependencies will be reviewed for security risks.
We ask researchers and contributors to:
- Avoid publicly disclosing vulnerabilities until a fix is released.
- Work with us privately to resolve issues responsibly.
By following responsible disclosure, you help protect the community of users relying on v-serpbear.