Thank you for helping keep Borda projects and their users safe! We take security seriously and appreciate responsible disclosure of any vulnerabilities.
Security updates are typically provided for the latest stable release of each project. Individual repositories may specify their own support policies if they differ from this default.
| Version | Supported |
|---|---|
| Latest stable release | β Yes |
| Older releases | |
| Release candidates (RC) | β No |
| Development (dev/nightly) | β No |
π‘ Tip: Always use the latest version to benefit from security patches and improvements.
Please do NOT report security vulnerabilities through public GitHub issues.
Instead, report security vulnerabilities through one of these private channels:
- GitHub Security Advisories (preferred) β Use the "Report a vulnerability" button on the repository's Security tab
- Private/Direct contact β Email the project maintainer directly if their contact information is available
When reporting a vulnerability, please provide:
- Description β A clear explanation of the vulnerability
- Impact β What could an attacker potentially do?
- Steps to reproduce β Detailed steps to demonstrate the issue
- Affected versions β Which versions are impacted?
- Suggested fix β If you have one (optional but appreciated)
After you submit a report:
| Timeline | Action |
|---|---|
| 48 hours | Acknowledgment of your report |
| 1-2 weeks | Initial assessment and severity determination |
| Ongoing | Updates on fix progress |
| Upon fix | Credit in release notes (unless you prefer anonymity) |
π We appreciate your patience. Open source maintainers often work on projects in their spare time.
When using Borda projects, we recommend:
- Keep dependencies updated β Regularly update to the latest versions
- Review security advisories β Watch repositories for security announcements
- Follow least privilege β Use minimal permissions required
- Validate inputs β Always sanitize external data in your applications
We believe in recognizing security researchers who help improve our projects:
- Public acknowledgment in release notes and security advisories
- Addition to a project's SECURITY.md acknowledgments section (if applicable)
- Our sincere gratitude for helping keep users safe
Questions about security? Contact the project maintainers privately.
Made with π by the Borda et al.