Skip to content

Security: lemon-ant/JHarmonizer

Security

.github/SECURITY.md

Security Policy

Supported versions

The latest stable release is supported. As of now, this means version 1.0.1.

Reporting a vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

To report a vulnerability, use one of the following options:

  1. GitHub Security Advisories (preferred): Open a private security advisory directly in this repository. GitHub keeps the report private and notifies the maintainers immediately.

  2. Email: Send a description of the vulnerability to antonlem78@gmail.com. Include as much detail as possible: affected version, steps to reproduce, potential impact, and any suggested fix.

Response timeline

  • Acknowledgement: within 5 business days of receiving the report.
  • Initial assessment: within 10 business days.
  • Fix and release: we aim to release a patch within 30 days of confirmation, depending on severity and complexity.

You will be credited in the release notes when the fix is published, unless you prefer to remain anonymous.

Scope

This policy covers the JHarmonizer source code, build configuration, and packaged artifacts published under io.github.lemon-ant.jharmonizer. Third-party dependencies are out of scope; please report those issues directly to the respective upstream projects.

There aren't any published security advisories