| Version | Supported |
|---|---|
| 0.x.x | ✅ |
We take security seriously. If you discover a security vulnerability, please report it responsibly.
- Do not open a public GitHub issue for security vulnerabilities.
- Email us at security@monodox.com with details of the vulnerability.
- Include the following in your report:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 5 business days
- Resolution: Depends on severity, typically within 30 days
- We will acknowledge your report promptly.
- We will investigate and validate the issue.
- We will work on a fix and coordinate disclosure with you.
- We will credit you in the release notes (unless you prefer to remain anonymous).
- Keep dependencies up to date
- Never commit secrets or credentials
- Use environment variables for sensitive configuration
- Follow the principle of least privilege
- Report suspicious activity to security@monodox.com