We actively provide security patches and bug fixes for the latest development branch and released versions:
| Version | Supported |
|---|---|
main (Latest) |
✅ |
| >= 0.1.0 | ✅ |
| < 0.1.0 | ❌ |
We take the security and integrity of TimeEngine seriously. If you discover a security vulnerability, please follow responsible disclosure practices:
- Do NOT disclose the vulnerability publicly (do not open public issues, discussions, or pull requests disclosing exploit details).
- Report via GitHub Private Security Advisories (Preferred):
- Navigate to the Security Advisories tab on GitHub.
- Click "Report a vulnerability" to draft a private advisory directly with maintainers.
- Report via Email:
- Alternatively, email the lead maintainer directly at
[email protected]with the subject[TimeEngine Security Vulnerability].
- Alternatively, email the lead maintainer directly at
- Include Detailed Information:
- Provide a clear description of the vulnerability.
- Include reproduction steps, proof-of-concept code, affected components/platforms, and potential impact.
- Initial Response: We will acknowledge receipt of your vulnerability report within 48 hours.
- Assessment & Triage: Maintainers will confirm the vulnerability and determine its severity and scope within 5 business days.
- Fix & Public Disclosure: A patch will be prepared in a private fork/security advisory and released alongside a security advisory disclosure once verified.