Skip to content

Security: involvex/Desk-Escape

.github/SECURITY.md

Security Policy

Supported Versions

The maintainers of Desk Escape release patches for security vulnerabilities only against the latest minor version available on the main branch. If you are using an older release, we strongly recommend upgrading before reporting a vulnerability.

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

We take the security of Desk Escape and our users' systems seriously. If you believe you have found a security vulnerability, please do not open a public GitHub issue. Instead, report it responsibly:

  • Email: support@involvex.dev
  • Subject line: prefix with SECURITY: so it is routed correctly.
  • Include:
    • A description of the vulnerability
    • Steps to reproduce
    • The version/commit you found it on
    • Your preferred method of attribution (if any)

What to expect

  • We will acknowledge receipt within 48 hours on business days.
  • We will investigate and may request additional information.
  • We will aim to release a fix or mitigation within 7 days for critical issues, or coordinate a disclosure timeline for less severe issues.
  • You will be notified when the fix is released. Please do not disclose the vulnerability publicly until a fix is available.

There aren't any published security advisories