Skip to content

Security: assada/dead-editor

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
latest
< 1.0

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

How to Report

  1. DO NOT open a public issue for security vulnerabilities
  2. Go to the Security Advisories page
  3. Click "Report a vulnerability"
  4. Provide a detailed description of the vulnerability

What to Include

  • Type of vulnerability
  • Full paths of source file(s) related to the vulnerability
  • Step-by-step instructions to reproduce
  • Proof-of-concept or exploit code (if possible)
  • Impact assessment

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Fix Timeline: Depends on severity
    • Critical: 24-72 hours
    • High: 1-2 weeks
    • Medium: 1 month
    • Low: Next release

Recognition

We appreciate responsible disclosure and will:

  • Credit reporters in release notes (unless anonymity is requested)
  • Consider bounties for critical vulnerabilities (if program exists)

Security Best Practices

When using DeadEditor:

  1. Always download from official sources (GitHub Releases)
  2. Verify checksums and signatures when available
  3. Keep your installation up to date
  4. Report suspicious behavior

There aren’t any published security advisories