| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability within Vetour, please report it privately via email to the project maintainer. Do not disclose vulnerabilities publicly until they have been addressed.
To report a vulnerability:
- Email the maintainer at the address listed in the profile.
- Include a detailed description of the vulnerability.
- Provide steps to reproduce the issue.
- If possible, include a proof of concept.
You can expect an acknowledgment within 48 hours, and a detailed response within 5 business days regarding the next steps.
Security issues include, but are not limited to:
- Remote code execution
- Arbitrary file read/write via the application
- Injection vulnerabilities
- Authentication bypass (for the deploy feature)
- Unsafe deserialization
The following are not considered security vulnerabilities:
- Missing security headers in development mode
- Dependency vulnerabilities in outdated packages (please update instead)
- Features explicitly disabled in the open-source build (see README)
If possible, please encrypt sensitive vulnerability reports using the maintainer's PGP key (if available).
We appreciate your help in keeping Vetour and its users safe.