Below is the list of versions currently receiving security updates:
| Version | Supported |
|---|---|
| 0.7.x | ❌ |
| 0.8.x | ❌ |
| 0.9.x | ✅ |
| 1.x.x | ✅ |
If you discover a security vulnerability within this project, please follow these steps to report it:
- Do NOT open a public issue. Please report any security vulnerabilities confidentially to avoid exposing risks to other users.
- Contact: Send an email with the details to mmdparsadev@gmail.com or use the Private Vulnerability Reporting feature on GitHub if enabled.
- Information to Include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue (code snippets, screenshots, or Proof of Concept).
- Response Time: You will receive an initial acknowledgment of your report within 48 hours.
- Status Updates: We will keep you updated on the progress of investigating and fixing the issue.
- Resolution: Once a fix is verified, a patch will be released, and you will be credited for the disclosure (if desired).
جدول زیر نسخههایی که در حال حاضر بهروزرسانیهای امنیتی دریافت میکنند را نشان میدهد:
| نسخه | پشتیبانی میشود |
|---|---|
| 0.7.x | ❌ |
| 0.8.x | ❌ |
| 0.9.x | ✅ |
| 1.x.x | ✅ |
اگر آسیبپذیری یا مشکل امنیتی در این پروژه پیدا کردید، لطفاً مراحل زیر را دنبال کنید:
۱. لطفاً Issue عمومی باز نکنید. برای جلوگیری از سوءاستفاده، گزارش خود را بهصورت محرمانه ارسال کنید. ۲. روش ارتباط: جزئیات را به ایمیل mmdparsadev@gmail.com بفرستید یا از بخش Private Vulnerability Reporting در گیتهاب استفاده کنید. ۳. اطلاعات مورد نیاز در گزارش:
- توضیح کامل آسیبپذیری و میزان خطرات آن.
- مراحل بازتولید مشکل (تکه کد، اسکرینشات یا اثبات مفهوم / PoC).
- زمان پاسخ اولیه: گزارش شما حداکثر ظرف ۴۸ ساعت بررسی و پاسخ داده میشود.
- اطلاعرسانی: مراحل بررسی و رفع مشکل به اطلاع شما خواهد رسید.
- برطرفسازی: پس از تأیید و رفع مشکل، یک بهروزرسانی جدید منتشر شده و (در صورت تمایل خودتان) از شما قدردانی خواهد شد.