The echoy team takes security seriously. We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.
We provide security updates for the following versions of echoy. Please ensure you are using a supported version.
| Version | Supported |
|---|---|
| [Latest Release] | ✅ |
| < 1.0 | ✅ |
Please do NOT report security vulnerabilities through public GitHub issues. Your security is important, and sensitive details should always be reported privately.
Please report potential vulnerabilities using one of the following private methods:
- (Recommended) Use GitHub Security Advisories. This is the preferred method as it allows for private discussion and tracking directly within GitHub.
- (Alternative Private Method) Email us directly at hello@shaharialab.com. Please use this for sensitive vulnerability details. Use a clear subject line like "Security Vulnerability Report for echoy".
What to include in your private report:
- A clear description of the vulnerability and its potential impact.
- Detailed steps to reproduce the vulnerability, including any specific configurations or prerequisites.
- Proof-of-concept code, screenshots, or logs if applicable.
- The version(s) of
echoyaffected. - Any potential mitigations or workarounds you are aware of.
Public Discussion Channel (Not for Sensitive Reports):
For general security questions or discussions (but NOT for reporting undisclosed sensitive vulnerabilities), you can also find us on our #echoy Discord channel. Please remember this is a public channel, so do not share sensitive information there before it has been privately reported and addressed.
- Acknowledgement: We aim to acknowledge receipt of your private vulnerability report within [e.g., 2-3 business days].
- Assessment: We will investigate the report to confirm the vulnerability and determine its severity.
- Updates: We will strive to keep you informed of our progress during the investigation and remediation process via the private channel you used.
- Remediation: We will work to develop and release a patch for the vulnerability in a timely manner, prioritizing based on severity.
- Disclosure: Once a fix is available, we may coordinate public disclosure with you. We typically aim to disclose vulnerabilities via GitHub Security Advisories after a patch is released. We appreciate responsible disclosure practices that allow users time to update before full technical details are made public.
We value your contributions to keeping echoy secure!