The maintainers of Desk Escape release patches for security vulnerabilities
only against the latest minor version available on the main branch. If you
are using an older release, we strongly recommend upgrading before reporting
a vulnerability.
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
We take the security of Desk Escape and our users' systems seriously. If you believe you have found a security vulnerability, please do not open a public GitHub issue. Instead, report it responsibly:
- Email:
support@involvex.dev - Subject line: prefix with
SECURITY:so it is routed correctly. - Include:
- A description of the vulnerability
- Steps to reproduce
- The version/commit you found it on
- Your preferred method of attribution (if any)
- We will acknowledge receipt within 48 hours on business days.
- We will investigate and may request additional information.
- We will aim to release a fix or mitigation within 7 days for critical issues, or coordinate a disclosure timeline for less severe issues.
- You will be notified when the fix is released. Please do not disclose the vulnerability publicly until a fix is available.