Skip to content

Security: iOSDG/KSCrash

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.x
1.x

Reporting a Vulnerability

If you discover a security vulnerability in KSCrash, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please use GitHub's private vulnerability reporting feature:

  1. Go to the Security tab of this repository
  2. Click "Report a vulnerability"
  3. Fill out the form with details about the vulnerability

What to Include

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any suggested fixes or mitigations (if known)

Response Timeline

  • Initial response: Within 72 hours
  • Status update: Within 7 days
  • Fix timeline: Depends on severity, typically within 30-90 days

Disclosure Policy

We follow responsible disclosure practices. Once a fix is available, we will:

  1. Release a patched version
  2. Publish a security advisory
  3. Credit the reporter (unless they prefer to remain anonymous)

Security Best Practices for Users

When using KSCrash in your application:

  • Always use the latest stable version
  • Review crash reports before transmitting them, as they may contain sensitive information
  • Use HTTPS endpoints for crash report submission
  • Consider the privacy implications of the data collected in crash reports

There aren’t any published security advisories