Use this section to tell people about which versions of your project are currently being supported with security updates.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take the security of unipm seriously. If you believe you have found a security vulnerability in unipm, please report it to us as described below.
Instead, please send an email to [atul.k.m@ieee.org].
You should expect to receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message.
Please include as much of the following information as possible in your report:
- The specific version of unipm affected.
- Steps to reproduce the issue.
- Any relevant configuration files or example code.
- A description of the impact of the vulnerability.
- Your name and affiliation (optional).
- Acknowledgment: We will acknowledge receipt of your report within 24 hours.
- Assessment: We will investigate the issue and determine its severity and impact. We may contact you for further information.
- Fix: If a vulnerability is confirmed, we will work on a fix. We will keep you updated on our progress.
- Disclosure: Once a fix is available and released, we will publicly disclose the vulnerability (with your permission, crediting you for the discovery). We aim to provide a reasonable amount of time for users to upgrade before disclosing full details.
- Review the CONTRIBUTING.md guide.
- Avoid committing secrets or sensitive information.
- Use the provided safety features (e.g., input sanitization) when developing new features.
- Run tests and security scans (once available) before submitting pull requests.
This security policy is part of the unipm project and is licensed under the MIT License.