| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take the security of HeaderQuarters very seriously. If you discover a security vulnerability, we ask that you report it to us privately so we can address it before it's publicly disclosed.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please send an email to: Security@thexholdings.com
- A descriptive summary of the vulnerability.
- Detailed reproduction steps.
- The perceived impact of the vulnerability.
- CRITICAL: Do NOT include any active secrets, API keys, or personal tokens in your reports or reproduction steps. Use dummy values.
- We will acknowledge receipt of your vulnerability report within 48 hours.
- We aim to triage and provide a fix or mitigation plan within 30 days.
In Scope:
- HeaderQuarters extension source code
- Build system configuration (Vite, Rollup)
- Project dependencies (if exploitable through the extension)
Out of Scope:
- Chrome browser bugs or inherent declarativeNetRequest limitations.
- Issues requiring enterprise policies or MDM to exploit.
- Physical access to an unlocked device.