Skip to content

Security: Sanjaya-Danushka/Neoarch

Security

SECURITY.md

Security Policy

Supported Versions

We actively support the following versions with security updates:

Version Supported
1.1.x
1.0.x
< 1.0

Reporting a Vulnerability

If you discover a security vulnerability in NeoArch, please report it to us as soon as possible. We take security seriously and will respond promptly.

How to Report

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by emailing: dsanjaya712@gmail.com

Include the following information in your report:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact and severity
  • Any suggested fixes or mitigations
  • Your contact information (optional)

What to Expect

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours
  2. Investigation: We will investigate the issue and determine its validity
  3. Updates: We will keep you informed about our progress
  4. Resolution: We will work to fix the vulnerability and release a security update
  5. Disclosure: We will coordinate disclosure timing with you

Responsible Disclosure

We kindly ask that you:

  • Give us reasonable time to fix the issue before public disclosure
  • Avoid accessing or modifying user data without permission
  • Keep the vulnerability confidential until we've released a fix

Security Updates

Security updates will be:

  • Released as soon as possible
  • Clearly marked as security fixes
  • Documented in release notes
  • Communicated through our channels

Recognition

We appreciate security researchers who help keep NeoArch safe. With your permission, we may acknowledge your contribution in our release notes or security acknowledgments.

Security Best Practices

For Users

  • Always download NeoArch from official sources
  • Keep your system and dependencies updated
  • Use strong authentication for package management
  • Be cautious with third-party plugins

For Developers

  • Follow secure coding practices
  • Validate all inputs
  • Use safe subprocess calls
  • Regularly audit dependencies
  • Implement proper error handling

Contact

For security-related questions or concerns:

Thank you for helping keep NeoArch secure!

There aren’t any published security advisories