Skip to content

Security: code-xon/sonora

Security

SECURITY.md

Security Policy

Supported Versions

We take security seriously. The following versions of Sonora are currently supported with security updates:

Version Supported
1.2.x
1.0.x
< 1.0

Reporting a Vulnerability

If you discover a security vulnerability in Sonora, please report it to us as follows:

Do not create a public GitHub issue for security vulnerabilities.

Instead, please email the lead developer directly:

Include the following information in your report:

  1. A clear description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact and severity
  4. Any suggested fixes or mitigations
  5. Your contact information for follow-up

Response Process

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours
  2. Investigation: We will investigate the issue and determine its validity
  3. Fix Development: If valid, we will develop and test a fix
  4. Disclosure: We will coordinate disclosure with you
  5. Release: We will release the fix and security advisory

Responsible Disclosure

We kindly ask that you:

  • Give us reasonable time to fix the issue before public disclosure
  • Avoid accessing or modifying user data
  • Do not perform DoS attacks or degrade services
  • Respect the privacy and security of our users

Recognition

We appreciate security researchers who help keep Sonora safe. With your permission, we will acknowledge your contribution in our security advisory.

Contact

For any security-related questions:

There aren’t any published security advisories