Skip to content

Security: utopia-dart/utopia_hotreload

Security

SECURITY.md

Security Policy

Supported Versions

We currently provide security updates for the following versions:

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please follow these guidelines:

Where to Report

Please DO NOT report security vulnerabilities through public GitHub issues.

Instead, please report them to:

What to Include

When reporting a vulnerability, please include:

  1. Description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact and attack scenarios
  4. Suggested fix (if you have one)
  5. Your contact information for follow-up

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity and complexity

Security Update Process

  1. Acknowledgment: We'll confirm receipt of your report
  2. Investigation: We'll investigate and validate the issue
  3. Fix Development: We'll develop and test a fix
  4. Coordinated Disclosure: We'll coordinate the release and disclosure
  5. Credit: We'll acknowledge your contribution (if desired)

Scope

This security policy applies to:

  • The utopia_hotreload package
  • Related infrastructure and documentation
  • Security issues that affect user applications

Out of Scope

The following are generally not considered security vulnerabilities:

  • Issues in third-party dependencies (please report to the respective maintainers)
  • Denial of service attacks requiring local system access
  • Issues requiring physical access to the system

Thank you for helping keep Utopia Hot Reload and our users safe!

There aren’t any published security advisories