| Version | Supported |
|---|---|
| latest | ✅ |
We take security seriously. If you discover a security vulnerability within the Apso CLI project, please report it to us as soon as possible.
Please DO NOT report security vulnerabilities through public GitHub issues.
Instead, please email security@apso.dev. We will acknowledge your email within 48 hours, and will send a more detailed response within 72 hours indicating the next steps in handling your report.
When reporting a vulnerability, please include the following information:
- A detailed description of the vulnerability: Explain the nature of the vulnerability, including how it can be exploited.
- Steps to reproduce: Provide clear, step-by-step instructions on how to reproduce the vulnerability.
- Affected component(s): Specify which part(s) of the project are affected.
- Potential impact: Describe the potential impact if the vulnerability is exploited.
- Proof of Concept (PoC): If possible, provide a PoC or sample code demonstrating the vulnerability.
- Your contact information: So we can follow up with you.
We appreciate your efforts to responsibly disclose your findings, and will make every effort to acknowledge your contributions.