Skip to content
This repository was archived by the owner on Mar 16, 2026. It is now read-only.

Security: Clement-Muth/Deazl

Security

SECURITY.md

Security Policy – Deazl

Supported Versions

The table below indicates which versions of Deazl currently receive security updates.

Version Supported
5.x.x
4.x.x
3.x.x
2.x.x
1.x.x
0.x.x

Note: Only the latest major release of Deazl receives security fixes. Older versions are not maintained unless explicitly stated.


Reporting a Vulnerability

We take the security of Deazl very seriously and encourage responsible disclosure from the community.

If you find a vulnerability, please follow the steps below.

📬 How to Report

  • Email us at clement.muth@deazl.fr

  • Use the subject line: Security Report – <short description>

  • Provide detailed information, including:

    • Steps to reproduce
    • Affected page(s) or API endpoint(s)
    • Expected vs actual behavior
    • Potential impact

🔒 Responsible Disclosure

  • Do not open a public GitHub issue.
  • Do not publicly disclose the vulnerability until a fix is released.
  • We may request additional technical information to verify the issue.

⏱ Expected Response Time

You can expect:

  • Acknowledgement within 72 hours
  • Initial assessment within 7 days
  • A fix or mitigation plan, depending on severity and complexity

🛠 After Validation

If the vulnerability is accepted:

  • The issue will be categorized by severity
  • A fix will be developed and deployed
  • You will be notified as soon as the patch is available
  • You may be credited in the release notes unless anonymity is requested

Additional Notes

  • Security fixes may be backported to previous versions only when the vulnerability is critical and technically feasible.
  • For urgent matters (e.g., active exploitation), please clearly indicate the severity in your email subject.

There aren't any published security advisories