31 lines
1.1 KiB
Markdown
31 lines
1.1 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
| Version | Supported |
|
|
|---------|-----------|
|
|
| 2.1.x | Yes |
|
|
| < 2.1 | No |
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
If you discover a security vulnerability in LANCommander, please report it responsibly.
|
|
|
|
**Do not open a public GitHub issue for security vulnerabilities.**
|
|
|
|
Instead, please report vulnerabilities by joining our [Discord](https://discord.gg/vDEEWVt8EM) and sending a direct message to a project maintainer, or by emailing the details privately.
|
|
|
|
### What to Include
|
|
|
|
- Description of the vulnerability
|
|
- Steps to reproduce
|
|
- Potential impact
|
|
- Suggested fix (if any)
|
|
|
|
### Response Timeline
|
|
|
|
We will acknowledge your report within 72 hours and aim to provide a fix or mitigation plan within 7 days for critical issues.
|
|
|
|
## Scope
|
|
|
|
LANCommander is designed to run on trusted local networks. While we take security seriously, the platform's primary use case assumes a trusted network environment (e.g., LAN parties). That said, we still want to address vulnerabilities that could affect users who expose their instance to broader networks.
|