Skip to content

Security: superezzdev/randall

Security

SECURITY.md

Security Policy

Supported Versions

Currently, only the latest version of this project is supported with security updates.

Version Supported
Latest
Older

Reporting a Vulnerability

DO NOT open a public issue to report a security vulnerability.

Instead, please use GitHub's private vulnerability reporting feature:

  1. Go to the Security tab of this repository.
  2. Click on Report a vulnerability to open a private advisory.

What to Include

When reporting a vulnerability, please provide the following information to help us understand and resolve the issue quickly:

  • Description: A detailed description of the vulnerability.
  • Steps to Reproduce: Clear, step-by-step instructions to reproduce the issue.
  • Potential Impact: An explanation of how this vulnerability could be exploited and what the potential impact would be.

Critical Priority: Camera and Microphone Access

Because this is a WebRTC application, we consider any security vulnerability related to unauthorized camera or microphone access, media stream leaks, or WebRTC connection hijacking as critical priority.

What to Expect

  • Acknowledgment: You can expect an acknowledgment of your report within 48 hours.
  • Fix Timeline: For critical issues, we aim to provide a fix within 14 days of confirming the vulnerability. For non-critical issues, timelines will vary based on severity and complexity.

Hall of Fame

We would like to thank the following individuals who have responsibly disclosed security vulnerabilities to us.

  • (Placeholder for acknowledged reporters)

There aren't any published security advisories