Security Policy
Supported Versions
Security updates are provided for the latest stable release of Shelf Drive.
Version| Supported Latest| Yes Older releases| No
Reporting a Vulnerability
If you discover a security vulnerability in Shelf Drive, please report it privately rather than opening a public GitHub issue.
When reporting a vulnerability, please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- The affected version or commit
- Potential security impact
- Any relevant logs, screenshots, or proof of concept
Please do not publicly disclose the vulnerability until it has been investigated and, where appropriate, a fix has been released.
Response
We will review valid security reports and investigate their impact. Depending on the severity, we may:
- Confirm the vulnerability.
- Assess its security impact.
- Develop and test a fix.
- Release a security update.
- Publish appropriate security information after remediation.
Scope
Security reports may include issues involving:
- Authentication and authorization
- File and data access
- Encryption and key handling
- API security
- Local privilege escalation
- Remote code execution
- Sensitive information disclosure
- Dependency vulnerabilities
- Data integrity or isolation
Safe Harbor
Good-faith security research is welcome. Please avoid accessing, modifying, or deleting data belonging to other users, disrupting services, or performing actions that could cause harm.
Thank you for helping keep Shelf Drive secure.