Skip to content

Security: Rexschwert/worldwideview

Security

SECURITY.md

Security Policy

Security is a priority for our project. We appreciate the efforts of security researchers and the open-source community in helping us keep our software secure.

Supported Versions

Security updates are provided for the following versions of the project. We highly recommend all users stay on the latest stable release.

Version Supported Notes
2.x.x Current main release. Receives all security updates.
1.x.x Legacy version. No longer receiving updates.
< 1.0 Beta versions are not supported.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you believe you have found a security vulnerability in this project, please report it privately so we have time to fix it before the vulnerability is made public.

How to Report

  1. Email us directly: Send your report to [support@worldwideview.dev].
  2. GitHub Security Advisories: Alternatively, if this repository has Private Vulnerability Reporting enabled, you can click on the Security tab -> Advisories -> Report a vulnerability.

What to Include

To help us quickly validate and fix the issue, please include the following in your report:

  • A description of the vulnerability and its potential impact.
  • The steps required to reproduce the issue (a proof of concept is highly appreciated).
  • Any relevant environment details (OS, browser, version).

What to Expect

  • Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours.
  • Triage & Fix: We will review the report, determine its severity, and work on a patch. We will keep you updated on our progress.
  • Disclosure: Once the vulnerability is patched and a new version is released, we will publish a security advisory. We are happy to credit you for the discovery if you would like!

Note: As an open-source project, we currently do not offer financial bug bounties, but we deeply appreciate your contributions to keeping our users safe.

There aren't any published security advisories