The DIVMORA Technologies team takes security seriously across all our open source and commercial products. We appreciate responsible disclosure of security vulnerabilities and are committed to addressing verified issues promptly.
Please refer to the SECURITY.md file in each individual project repository for specific version support tables. By default, only the latest active release branch of any project receives security updates.
Important
Please do not report security vulnerabilities via public GitHub issues, discussions, or pull requests.
If you discover a security vulnerability in any Divmora project:
- Email: Send details to [email protected].
- GitHub Security Advisory: Submit a private vulnerability report directly via the specific repository's Security tab ➔ Report a vulnerability.
To help us investigate and reproduce the issue efficiently, please provide:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions or a minimal proof-of-concept (PoC).
- Affected repository, component(s), versions, and environment configuration.
- Any suggested mitigations or patches (if available).
- Acknowledgement: We will acknowledge receipt of your report within 48 hours.
- Triage & Assessment: Our engineering team will investigate and confirm the issue, keeping you informed.
- Fix & Validation: A fix will be developed, tested, and prepared for release.
- Coordinated Disclosure: We will coordinate release of the security advisory crediting you for responsible disclosure.