44 lines
1.7 KiB
Markdown
44 lines
1.7 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
The following versions of OxiCloud are currently supported with security updates:
|
|
|
|
| Version | Supported |
|
|
| ------- | ------------------ |
|
|
| Latest | :white_check_mark: |
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
The OxiCloud team takes security issues seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.
|
|
|
|
To report a security vulnerability, please follow these steps:
|
|
|
|
1. **DO NOT** disclose the vulnerability publicly (e.g., in GitHub issues)
|
|
2. Email details of the vulnerability to the project maintainers
|
|
3. Include as much information as possible, such as:
|
|
- A clear description of the vulnerability
|
|
- Steps to reproduce the issue
|
|
- Potential impact
|
|
- Suggested fixes if available
|
|
|
|
## What to Expect
|
|
|
|
After submitting a vulnerability report, you can expect the following:
|
|
|
|
1. **Acknowledgment**: The team will acknowledge receipt of your report within 3 business days
|
|
2. **Assessment**: We'll evaluate the vulnerability and determine its impact
|
|
3. **Plan**: We'll develop a plan to address the vulnerability
|
|
4. **Fix & Release**: Once fixed, we'll release an update
|
|
5. **Recognition**: With your permission, we'll acknowledge your contribution in the release notes
|
|
|
|
## Security Best Practices for OxiCloud Users
|
|
|
|
- Keep your OxiCloud installation updated to the latest version
|
|
- Use strong, unique passwords for all user accounts
|
|
- Configure proper file permissions
|
|
- Regularly back up your data
|
|
- Consider running OxiCloud behind a reverse proxy with HTTPS
|
|
- Implement IP restrictions where appropriate
|
|
|
|
Thank you for helping keep OxiCloud and its users secure! |