Skip to content

Security: SQLoot/evolu-plan-b

SECURITY.md

Security Policy

Reporting Security Vulnerabilities

If you discover a security vulnerability in this fork, please help keep the project secure by disclosing it responsibly.

How to Report

Please DO NOT open a public GitHub issue for security vulnerabilities.

Instead, use GitHub's private vulnerability reporting for this repository:

If the issue appears to affect upstream as well, you can additionally report it upstream:

Response Time

As this project is maintained by a single volunteer, please be patient.

Security Considerations

Important Notice

While this fork is developed with care, please note:

  • This is a volunteer-maintained project
  • It has NOT undergone professional security audits yet
  • Use in production or security-critical contexts is at your own risk

Disclosure Policy

When a vulnerability is confirmed:

  1. A fix will be developed privately
  2. A new version will be released with the fix
  3. The vulnerability will be disclosed in the release notes after users have had time to upgrade

For non-security issues, please use GitHub Issues.

There aren’t any published security advisories