We take the security of OninOneProxy seriously. If you believe you have discovered a security vulnerability, please follow the process below.
Security vulnerabilities must not be reported via the public GitHub Issue tracker. Publicly disclosing a vulnerability before a fix is available puts users at risk.
Please report security issues through GitHub Security Advisory:
- Go to https://github.com/Vincent-A-Yang/OninOneProxy/security/advisories/new
- Fill in the advisory form with:
- A description of the vulnerability
- Steps to reproduce or a proof of concept
- The affected version(s)
- Any suggested mitigation
You can also use the "Report a vulnerability" button on the repository's Security tab.
We aim to acknowledge receipt of security reports within 72 hours and to provide an initial assessment within 7 days.
We follow a coordinated disclosure model:
- We confirm the vulnerability and assess its impact.
- We develop and test a fix.
- We release a patched version and publish a security advisory with credit to the reporter (unless anonymity is requested).
- Public disclosure happens after a fix is available.
Only the latest release line receives security updates. Older versions are supported on a best-effort basis.
| Version | Supported |
|---|---|
| 0.5.x | ✅ Active |
| < 0.5 | ❌ Not supported |
OninOneProxy is a derivative work based on 9Router by decolua, used under the MIT License. Security-relevant upstream fixes are tracked and ported when applicable.
This project is licensed under the MIT License. See LICENSE for details.