Below are the versions of Sotto that currently receive security updates:
| Version | Supported |
|---|---|
| 0.7.x | ✅ |
| < 0.7 | ❌ |
If you discover a security vulnerability within Sotto, please report it as soon as possible. You can report vulnerabilities using either of the following methods:
-
Email (Recommended for private reporting): Send a detailed email to report@sotto.auttomus.xyz.
-
GitHub Issues (For public tracking): Open a new issue in the GitHub Issues section of our repository.
To help us investigate and resolve the issue quickly, please include as much of the following information as possible:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions (or a proof-of-concept script/screenshot) to reproduce the behavior.
- Details of the environment used during testing (e.g., browser version, OS, NestJS/React Router version).
After receiving a report, we will:
- Acknowledge receipt of the report within 48 hours.
- Investigate the issue and work on a fix/patch.
- Keep you updated on the progress and notify you once a security update has been released.