Skip to content

Security: shadowofficial206/shadowdocs

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.2.x ✓ ✅
1.1.x ✓ ✅
< 1.1

Reporting a Vulnerability

If you discover a security vulnerability within ShadowDocs, please send an email to security@shadowdocs.app.

All security vulnerabilities will be promptly addressed.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Scope

  • API key exposure vulnerabilities
  • Code injection risks
  • Data privacy issues
  • Authentication/authorization bypasses

Out of Scope

  • Social engineering attacks
  • Physical security
  • Denial of service (unless severe)
  • Issues in third-party dependencies (report to maintainers)

Response Timeline

  • Acknowledge: 24-48 hours
  • Initial assessment: 3-5 days
  • Fix released: Based on severity

Security Updates

Security updates will be released as patch versions and announced on:

  • GitHub Security Advisories
  • npm security alerts

Do not open public issues for security vulnerabilities.

There aren't any published security advisories