Skip to content

Security: iwatkot/maps4fs

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of maps4fs are currently being supported with security updates:

Version Supported
2.x.x
< 2.0.0

Note: Only the latest release and the current major.minor version (2.x.x) receive security updates. Older versions are not supported.

Reporting a Vulnerability

If you discover a security vulnerability in maps4fs, please report it responsibly by following these steps:

How to Report

  1. Do not create a public GitHub issue for security vulnerabilities
  2. Do send an email to [email protected] with the subject line "Security Vulnerability in maps4fs"
  3. Include the following information in your report:
    • A detailed description of the vulnerability
    • Steps to reproduce the issue
    • Potential impact and severity
    • Any suggested fixes or mitigations
    • Your contact information for follow-up

What to Expect

  • Acknowledgment: You will receive an acknowledgment of your report within 48 hours
  • Initial Response: We will provide an initial response within 5 business days
  • Updates: We will keep you informed of our progress throughout the investigation
  • Resolution: We aim to resolve security issues as quickly as possible, typically within 30 days

Responsible Disclosure

We kindly ask that you:

  • Give us reasonable time to investigate and fix the issue before public disclosure
  • Avoid accessing, modifying, or deleting data that doesn't belong to you
  • Do not perform actions that could harm the service or its users
  • Do not disclose the vulnerability publicly until we have had a chance to address it

Recognition

We appreciate security researchers who help keep maps4fs and its users safe. If you responsibly disclose a security vulnerability, we will:

  • Acknowledge your contribution in our security advisories (if you wish)
  • Work with you to understand and resolve the issue
  • Keep you informed throughout the process

Thank you for helping to keep maps4fs secure!

There aren’t any published security advisories