Skip to content

Security: SRInternet-Studio/FactLite

Security

SECURITY.md

Security Policy

Supported Versions

Currently, only the latest version of FactLite is supported with security updates. We recommend always using the most recent version to ensure you have the latest security fixes.

Version Supported
1.2.0
< 1.2.0

Reporting a Vulnerability

If you discover a security vulnerability in FactLite, we encourage you to report it responsibly. We take all security vulnerabilities seriously and will respond promptly to address them.

How to Report

To report a security vulnerability, please send an email to:

admin@sr-studio.cn

Please include the following information in your report:

  1. A clear description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact of the vulnerability
  4. Any possible mitigations you have identified
  5. Your contact information for follow-up questions

What to Expect

When we receive a security vulnerability report, we will:

  1. Acknowledge receipt of your report within 24-72 hours
  2. Investigate the issue to verify its validity
  3. Determine the severity of the vulnerability
  4. Develop and test a fix
  5. Release a security update as soon as possible
  6. Credit you for the discovery (if you wish to be credited)

Timeline

  • Initial response: Within 24-72 hours of receiving your report
  • Investigation: 1-7 business days
  • Fix development: 3-14 business days (depending on severity)
  • Release: As soon as the fix is ready and tested

Security Updates

Security updates will be included in regular version releases. We will also announce critical security fixes through:

  • GitHub releases
  • PyPI release notes
  • The project's README file

Responsible Disclosure

We appreciate responsible disclosure of security vulnerabilities. Please do not publicly disclose the vulnerability until we have had a chance to address it.

Scope

This security policy applies to the FactLite framework and its official dependencies. It does not cover third-party libraries or applications that use FactLite.

Contact

For any security-related questions or concerns, please contact us at:

Email: srinternet@qq.com Project: https://github.com/SRInternet-Studio/FactLite

Thank you for helping to keep FactLite secure!

There aren't any published security advisories