Skip to content

Security: untacorp/sotto

SECURITY.md

Security Policy

Supported Versions

Below are the versions of Sotto that currently receive security updates:

Version Supported
0.7.x
< 0.7

Reporting a Vulnerability

If you discover a security vulnerability within Sotto, please report it as soon as possible. You can report vulnerabilities using either of the following methods:

  1. Email (Recommended for private reporting): Send a detailed email to report@sotto.auttomus.xyz.

  2. GitHub Issues (For public tracking): Open a new issue in the GitHub Issues section of our repository.

What to Include in a Report

To help us investigate and resolve the issue quickly, please include as much of the following information as possible:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions (or a proof-of-concept script/screenshot) to reproduce the behavior.
  • Details of the environment used during testing (e.g., browser version, OS, NestJS/React Router version).

Our Response Process

After receiving a report, we will:

  1. Acknowledge receipt of the report within 48 hours.
  2. Investigate the issue and work on a fix/patch.
  3. Keep you updated on the progress and notify you once a security update has been released.

There aren't any published security advisories