Skip to content

Latest commit

Β 

History

History
92 lines (60 loc) Β· 3.5 KB

File metadata and controls

92 lines (60 loc) Β· 3.5 KB

Security Policy

Supported Versions

We actively support the following versions of Evolution Manager with security updates:

Version Supported
2.x.x βœ… Yes
1.x.x ⚠️ Critical fixes only
< 1.0 ❌ No

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security vulnerability in Evolution Manager, please help us by reporting it responsibly.

πŸ”’ Private Disclosure Process

Please DO NOT create a public GitHub issue for security vulnerabilities.

Instead, please report security vulnerabilities by emailing us directly at:

πŸ“§ contato@evolution-api.com

πŸ“‹ What to Include

When reporting a vulnerability, please include:

  1. Description: A clear description of the vulnerability
  2. Steps to Reproduce: Detailed steps to reproduce the issue
  3. Impact: What an attacker could achieve by exploiting this vulnerability
  4. Affected Versions: Which versions of Evolution Manager are affected
  5. Proof of Concept: If possible, include a proof of concept (but please be responsible)
  6. Suggested Fix: If you have ideas for how to fix the issue

⏱️ Response Timeline

We are committed to responding to security vulnerability reports in a timely manner:

  • Initial Response: Within 48 hours of receiving your report
  • Status Updates: Every 7 days until the issue is resolved
  • Resolution: We aim to resolve critical vulnerabilities within 30 days

πŸ† Recognition

We believe in recognizing security researchers who help make Evolution Manager safer:

  • Hall of Fame: We maintain a security researchers hall of fame
  • CVE Assignment: For significant vulnerabilities, we'll work with you on CVE assignment
  • Public Recognition: With your permission, we'll publicly acknowledge your contribution

πŸ›‘οΈ Security Best Practices

When using Evolution Manager, we recommend:

  1. Keep Updated: Always use the latest supported version
  2. Secure Configuration: Follow our security configuration guidelines
  3. Network Security: Use HTTPS and proper network security measures
  4. Access Control: Implement proper authentication and authorization
  5. Regular Audits: Conduct regular security audits of your deployment

πŸ“š Security Resources

  • Security Documentation: [Link to security docs when available]
  • Security Checklist: [Link to security checklist when available]
  • Best Practices Guide: [Link to best practices when available]

🀝 Coordinated Disclosure

We follow responsible disclosure practices:

  1. Private Report: You report the vulnerability privately
  2. Investigation: We investigate and develop a fix
  3. Coordination: We coordinate with you on disclosure timing
  4. Public Disclosure: We publicly disclose the vulnerability after a fix is available

βš–οΈ Legal

This security policy is designed to be compatible with responsible security research. We will not pursue legal action against researchers who:

  • Follow this responsible disclosure process
  • Do not access or modify user data beyond what's necessary to demonstrate the vulnerability
  • Do not perform testing on production systems without permission
  • Do not engage in activities that could harm our users or services

Thank you for helping keep Evolution Manager and our community safe! πŸ™


Evolution Manager Security Team πŸ“§ contato@evolution-api.com 🌐 https://github.com/EvolutionAPI/evolution-manager-v2