We are committed to ensuring the security of the Public Detective project. Below is a list of versions that are currently supported with security updates.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
As the project is in its early stages, we recommend always using the latest version available.
We take all security vulnerabilities seriously. If you discover a security issue, please report it to us privately to protect the project and its users.
Please email a detailed report to mthunsche+public-detective@gmail.com.
Your report should include:
- A clear description of the vulnerability.
- Steps to reproduce the issue.
- The affected version(s).
- Any potential impact you have identified.
When you report a vulnerability, we commit to the following:
- We will acknowledge receipt of your report within 3 business days.
- We will provide you with a timeline for addressing the vulnerability and keep you updated on our progress.
- We will notify the community once the vulnerability has been patched. We will credit you for your discovery unless you prefer to remain anonymous.
Our security policy covers vulnerabilities found in the following areas:
- The main application code located in the
source/directory. - The project's infrastructure configuration if it poses a direct security risk.
The following issues are considered out of scope for our vulnerability disclosure program:
- Attacks requiring physical access to a user's device or the server.
- Social engineering attacks (e.g., phishing, vishing).
- Issues related to third-party services or dependencies (please report those to the respective service or library maintainers).
- Denial-of-service attacks that are not resource exhaustion issues.
- Reports of missing security headers that do not lead to a direct vulnerability.
We consider security research conducted under this policy to be authorized and will not pursue legal action against you. We ask that you make a good faith effort to avoid privacy violations, degradation of our services, or destruction of data.
Thank you for helping keep Public Detective and our users safe.