Use this section to tell people about which versions of your project are currently being supported with security updates.
Version | Supported |
---|---|
1.0.x | ✅ |
< 1.0 | ❌ |
If you discover a security vulnerability within Minerva, please send an email to [email protected]. All security vulnerabilities will be promptly addressed.
Please include the following information (if possible):
- Component(s) affected
- A description of the vulnerability
- Steps to reproduce
- Possible impacts
- Suggested fixes (if any)
- You'll receive acknowledgment of your report within 48 hours
- We'll investigate and keep you updated on our findings
- Once fixed, we'll notify you and publicly acknowledge your responsible disclosure
When using Minerva in your projects:
- Always use the latest version
- Regularly check for updates
- Follow our security guidelines in the documentation
- Implement proper Content Security Policy (CSP) headers
- Use HTTPS in production environments
When we receive a security bug report, we will:
- Confirm the problem and determine affected versions
- Audit code to find any similar problems
- Prepare fixes for all supported versions
- Release new versions and update documentation