| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
The DevShield team takes security seriously.
If you discover a security vulnerability, please do not open a public GitHub issue.
Instead, report it privately.
Email:
or
Open a confidential security advisory through GitHub.
- Description of the vulnerability
- Steps to reproduce
- Impact
- Affected version
- Proof of Concept (if available)
- Suggested remediation (optional)
| Stage | Target |
|---|---|
| Initial Response | 48 hours |
| Investigation | 5 business days |
| Security Fix | As soon as possible |
| Public Disclosure | After a patch is available |
We appreciate reports involving:
- Remote Code Execution
- SQL Injection
- Command Injection
- Authentication Bypass
- Authorization Issues
- Path Traversal
- SSRF
- XSS
- Prototype Pollution
- Sensitive Data Exposure
- Dependency Vulnerabilities
- GitHub Action Security
The following are generally not considered security vulnerabilities:
- Typographical errors
- Documentation issues
- Feature requests
- Rate limiting suggestions
- Denial of Service requiring unrealistic resources
- Social engineering attacks
Thank you for helping keep DevShield secure.