Skip to content

Security: mmdparsa-dev/Cheghad

SECURITY.md

Security Policy

Supported Versions

Below is the list of versions currently receiving security updates:

Version Supported
0.7.x
0.8.x
0.9.x
1.x.x

Reporting a Vulnerability

If you discover a security vulnerability within this project, please follow these steps to report it:

  1. Do NOT open a public issue. Please report any security vulnerabilities confidentially to avoid exposing risks to other users.
  2. Contact: Send an email with the details to mmdparsadev@gmail.com or use the Private Vulnerability Reporting feature on GitHub if enabled.
  3. Information to Include:
    • A description of the vulnerability and its potential impact.
    • Steps to reproduce the issue (code snippets, screenshots, or Proof of Concept).

What to Expect

  • Response Time: You will receive an initial acknowledgment of your report within 48 hours.
  • Status Updates: We will keep you updated on the progress of investigating and fixing the issue.
  • Resolution: Once a fix is verified, a patch will be released, and you will be credited for the disclosure (if desired).

سیاست‌های امنیتی (Security Policy)

نسخه‌های پشتیبانی‌شده

جدول زیر نسخه‌هایی که در حال حاضر به‌روزرسانی‌های امنیتی دریافت می‌کنند را نشان می‌دهد:

نسخه پشتیبانی می‌شود
0.7.x
0.8.x
0.9.x
1.x.x

گزارش آسیب‌پذیری‌های امنیتی

اگر آسیب‌پذیری یا مشکل امنیتی در این پروژه پیدا کردید، لطفاً مراحل زیر را دنبال کنید:

۱. لطفاً Issue عمومی باز نکنید. برای جلوگیری از سوءاستفاده، گزارش خود را به‌صورت محرمانه ارسال کنید. ۲. روش ارتباط: جزئیات را به ایمیل mmdparsadev@gmail.com بفرستید یا از بخش Private Vulnerability Reporting در گیت‌هاب استفاده کنید. ۳. اطلاعات مورد نیاز در گزارش:

  • توضیح کامل آسیب‌پذیری و میزان خطرات آن.
  • مراحل بازتولید مشکل (تکه کد، اسکرین‌شات یا اثبات مفهوم / PoC).

روند بررسی و پاسخ‌گویی

  • زمان پاسخ اولیه: گزارش شما حداکثر ظرف ۴۸ ساعت بررسی و پاسخ داده می‌شود.
  • اطلاع‌رسانی: مراحل بررسی و رفع مشکل به اطلاع شما خواهد رسید.
  • برطرف‌سازی: پس از تأیید و رفع مشکل، یک به‌روزرسانی جدید منتشر شده و (در صورت تمایل خودتان) از شما قدردانی خواهد شد.

There aren't any published security advisories