Only the latest stable version of WhatNull receives security updates.
| Version | Supported |
|---|---|
| < 0.1.0 | No |
If you discover a security vulnerability, please do not open a public GitHub issue. Send a report via email to security@whatnull.io (or the repository maintainers).
Please include the following details in your report:
- A descriptive title.
- Impact details and potential scenarios.
- Detailed steps to reproduce the vulnerability (proof of concept).
- Any configuration details required.
We will acknowledge receipt within 48 hours and work on a fix as quickly as possible.
Any security research conducted in good faith, following this policy, is protected. We will not pursue legal action for research that adheres to these guidelines.
Once a vulnerability is reported, we follow a responsible disclosure process:
- Verify the report and assess impact.
- Develop and test a patch.
- Release a new version with the patch.
- Publish a security advisory with credit to the researcher (if desired).