2020-08-21 18:54:37 +03:00
|
|
|
# Security Policy
|
|
|
|
|
|
|
|
## Supported Versions
|
|
|
|
|
2020-09-24 12:28:57 +03:00
|
|
|
Only the most recent stable version is supported.
|
2020-08-21 18:54:37 +03:00
|
|
|
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
|
2020-08-31 21:38:16 +03:00
|
|
|
Please report any security issues via email to security@getontracks.org.
|
|
|
|
If you don't get a reply for your email, resend the email after one week.
|
|
|
|
If there's still no reply, open an issue in the issue queue but *do not
|
|
|
|
disclose the details* in the issue, only ask about the reply and status.
|
2020-08-21 18:54:37 +03:00
|
|
|
|
2020-08-31 21:38:16 +03:00
|
|
|
You can (and should) encrypt the email you send with OpenGPG key
|
|
|
|
0x8af45b6854414d2d, which you can find for example in pool.sks-keyservers.net.
|
|
|
|
|
|
|
|
Unfortunately Tracks is not part of a bug bounty program, but we do provide
|
|
|
|
appropriate credits for disclosing security issues.
|