The Vidonex team takes security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings.
Only the latest minor release receives security patches. We encourage all users to upgrade to the latest stable version.
| Version | Supported |
|---|---|
v1.x |
✅ |
< 1.0 |
❌ |
If you discover a potential security vulnerability in Vidonex, please report it via one of the following methods:
- GitHub Security Advisory (Recommended): Use the GitHub Security Advisory form to privately report security bugs.
- Email: Send details of the vulnerability to security@vidonex.io.
- A clear description of the vulnerability.
- Steps to reproduce or a minimal proof of concept (PoC) timeline script.
- Potential impact and affected components (
compiler,executor,server, etc.). - Any suggested fixes or mitigations.
- We will acknowledge receipt of your vulnerability report within 48 hours.
- We will provide a timeline for triage and fix development.
- We will notify you once a patch has been merged and a security release is published.
- We will credit you in our security advisories (unless you request anonymity).
Please do NOT disclose security vulnerabilities publicly via GitHub Issues, Discussions, or social media until a fix has been released.