| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
DO NOT open public issues for security vulnerabilities.
Please report security vulnerabilities to: [your-email@domain.com]
- Initial response: 48 hours
- Status update: 7 days
- Fix timeline: 30 days (depending on severity)
- Dependabot automatically creates PRs for security updates
- Security PRs are labeled with
securityand prioritized - All security updates undergo automated testing before merge
- Critical vulnerabilities (CVSS >= 7.0) are patched within 24-48 hours
- All API endpoints implement rate limiting
- Input validation on all user-provided data
- Parameterized queries for database operations (PostgreSQL)
- JWT tokens with short expiration times
- HTTPS enforced in production
- Environment variables for sensitive configuration
- Regular dependency audits via
pip-auditandnpm audit