|
| 1 | +# Security Policy |
| 2 | + |
| 3 | +## Supported Versions |
| 4 | + |
| 5 | +We provide security updates for the following versions of Laravel Arc: |
| 6 | + |
| 7 | +| Version | Supported | |
| 8 | +| ------- | ------------------ | |
| 9 | +| 1.x | :white_check_mark: | |
| 10 | + |
| 11 | +## Reporting a Vulnerability |
| 12 | + |
| 13 | +If you discover a security vulnerability within Laravel Arc, please send an email to [[email protected]](mailto:[email protected]). All security vulnerabilities will be promptly addressed. |
| 14 | + |
| 15 | +Please do **not** report security issues publicly via GitHub issues or discussions. Security reports sent to the maintainer's email will be acknowledged within 48 hours. |
| 16 | + |
| 17 | +## Security Disclosure Process |
| 18 | + |
| 19 | +When reporting a security vulnerability, please include: |
| 20 | + |
| 21 | +1. **Description** - A clear description of the vulnerability |
| 22 | +2. **Impact** - What kind of vulnerability it is and who it impacts |
| 23 | +3. **Reproduction** - Detailed steps to reproduce the issue |
| 24 | +4. **Proof of Concept** - If applicable, include proof-of-concept code |
| 25 | +5. **Suggested Fix** - If you have ideas for how to fix the issue |
| 26 | + |
| 27 | +## Security Response Timeline |
| 28 | + |
| 29 | +- **Initial Response**: Within 48 hours of receiving the report |
| 30 | +- **Investigation**: We will investigate and validate the reported vulnerability |
| 31 | +- **Fix Development**: Development of a patch or mitigation strategy |
| 32 | +- **Release**: Coordinated disclosure and release of security update |
| 33 | +- **Public Disclosure**: After users have had time to upgrade |
| 34 | + |
| 35 | +## Security Best Practices |
| 36 | + |
| 37 | +When using Laravel Arc in your applications, we recommend: |
| 38 | + |
| 39 | +1. **Keep Updated** - Always use the latest version of Laravel Arc |
| 40 | +2. **Validate Input** - Ensure proper validation of all data passed to DTOs |
| 41 | +3. **Review Dependencies** - Regularly update your Composer dependencies |
| 42 | +4. **Follow Laravel Security** - Follow Laravel's security best practices |
| 43 | + |
| 44 | +## Bug Bounty Program |
| 45 | + |
| 46 | +We do not currently offer a bug bounty program, but we deeply appreciate responsible disclosure of security vulnerabilities. |
| 47 | + |
| 48 | +## Contact |
| 49 | + |
| 50 | +For security-related questions or concerns, please contact: |
| 51 | + |
| 52 | +- **Maintainer**: Jean-Marc Strauven |
| 53 | + |
| 54 | +Thank you for helping keep Laravel Arc and our users safe! |
0 commit comments