Skip to content

Security: wgtechlabs/nuvex

SECURITY.md

πŸ”’ Security Policy

🚨 Reporting Security Vulnerabilities

We take security seriously. If you discover a security vulnerability, please report it responsibly:

Private Vulnerability Reporting (Recommended)

This repository has private vulnerability reporting enabled. You can securely report vulnerabilities directly through GitHub:

  1. Navigate to the Security tab
  2. Click Advisories
  3. Click "Report a vulnerability" button
  4. Fill out the vulnerability details

This allows us to discuss and fix the issue privately before any public disclosure.

Email Reporting

Alternatively, you can email us at [email protected]

Please do NOT report security vulnerabilities through public GitHub issues.

What to Include

  • Clear description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Your environment details (Node.js version, OS, etc.)

Response Timeline

  • Initial Response: Within 48 hours
  • Status Updates: Every 3-5 business days
  • Resolution: Critical issues resolved within 7 days

πŸ›‘οΈ Supported Versions

We provide security updates for the following versions. If you're using an unsupported version, please upgrade to receive security patches.

Version Supported
>= 1.0.0 βœ… Yes
< 1.0.0 ❌ No

πŸ” Security Best Practices

When contributing or deploying:

  • βœ… Never commit secrets, API keys, or credentials
  • βœ… Always use environment variables for sensitive data
  • βœ… Keep dependencies updated
  • βœ… Use HTTPS/TLS for all endpoints
  • βœ… Enable security scanning (Dependabot, CodeQL)

πŸ† Recognition

While we don't offer monetary rewards, we deeply value security researchers and provide:

  • Public acknowledgment in security advisories (with permission)
  • Recognition in our security contributors hall of fame
  • Professional references for your security work

Thank you for helping keep our projects secure! πŸ™


πŸ” with ❀️ by Waren Gonzaga under WG Technology Labs and Him πŸ™

There aren’t any published security advisories