Skip to content

Security: file-conversor/file_conversor

Security

SECURITY.md

Security Policy

Supported Versions

Please use this section to determine if the version of the software you are using is currently supported with security updates. We only provide security updates for the versions listed below.

Version Supported Notes
latest Currently actively maintained.
< 0.7.x End of life. No longer receiving updates.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability within the project, please send an email to our team at fileconversor [a-t] gmail [d-o-t] com.

What to include in your report:

To help us triage and resolve the issue quickly, please include the following details in your report:

  • The type of vulnerability (e.g., XSS, SQLi, RCE).
  • Step-by-step instructions to reproduce the vulnerability.
  • Any proof-of-concept (PoC) code, screenshots, logs, stacktraces, etc.
  • The impact of the vulnerability.
  • Solution proposal (optional, but very welcome :-) ).

What to expect:

  1. We will triage the report and provide an estimated timeline for resolution.
  2. We ask that you maintain strict confidentiality until we have patched the vulnerability and released an update.
  3. Once the issue is resolved, we will publish a security advisory and, if you wish, credit you for the discovery.

Scope

This security policy applies strictly to the source code contained in this repository.

Out of Scope:

  • Vulnerabilities in third-party dependencies (please report these to the respective upstream maintainers).
  • Bugs that do not pose a security risk (please open a standard GitHub Issue for these).
  • Prior to posting Issues or Discussions, please consider verifying if another GitHub Issue or Discussion has been posted about the topic.

There aren't any published security advisories