Security is a priority for our project. We appreciate the efforts of security researchers and the open-source community in helping us keep our software secure.
Security updates are provided for the following versions of the project. We highly recommend all users stay on the latest stable release.
| Version | Supported | Notes |
|---|---|---|
| 2.x.x | ✅ | Current main release. Receives all security updates. |
| 1.x.x | ❌ | Legacy version. No longer receiving updates. |
| < 1.0 | ❌ | Beta versions are not supported. |
Please do not report security vulnerabilities through public GitHub issues.
If you believe you have found a security vulnerability in this project, please report it privately so we have time to fix it before the vulnerability is made public.
- Email us directly: Send your report to [support@worldwideview.dev].
- GitHub Security Advisories: Alternatively, if this repository has Private Vulnerability Reporting enabled, you can click on the
Securitytab ->Advisories->Report a vulnerability.
To help us quickly validate and fix the issue, please include the following in your report:
- A description of the vulnerability and its potential impact.
- The steps required to reproduce the issue (a proof of concept is highly appreciated).
- Any relevant environment details (OS, browser, version).
- Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours.
- Triage & Fix: We will review the report, determine its severity, and work on a patch. We will keep you updated on our progress.
- Disclosure: Once the vulnerability is patched and a new version is released, we will publish a security advisory. We are happy to credit you for the discovery if you would like!
Note: As an open-source project, we currently do not offer financial bug bounties, but we deeply appreciate your contributions to keeping our users safe.