We actively provide security updates for the following versions of Open Comet:
| Version | Supported |
|---|---|
| v1.1.x | ✅ |
| v1.0.x | ❌ |
We take the security of Open Comet seriously. If you believe you have found a security vulnerability, please report it to us responsibly.
Please do not open a public issue for security vulnerabilities.
Instead, please send an email to [INSERT SECURITY EMAIL ADDRESS].
To help us address the issue quickly, please include:
- Description: A clear description of the vulnerability.
- Steps to Reproduce: Detailed steps or a proof-of-concept (PoC) to reproduce the issue.
- Impact: What could an attacker do if they exploited this?
- Environment: Version of Open Comet, OS, and browser.
- Acknowledgment: We will acknowledge receipt of your report within 48 hours.
- Investigation: We will investigate the issue and determine its severity.
- Fix: If confirmed, we will work on a fix and release it as soon as possible.
- Public Disclosure: Once the fix is released, we will coordinate with you on public disclosure.
Thank you for helping keep Open Comet secure!