Only the latest release receives security updates. Please upgrade to the latest version before reporting an issue.
Please report security issues privately — do not open a public issue, pull request, or discussion.
- Preferred: GitHub private vulnerability reporting — open the repository's Security tab and choose "Report a vulnerability" (https://github.com/denho/faved/security/advisories/new).
- Alternatively: email security@faved.to.
Please include what you can:
- the affected version or commit;
- the component/endpoint involved and a description of the issue;
- reproduction steps or a proof of concept;
- your assessment of the impact.
- Acknowledgement within 2 business days.
- We confirm the issue, assess severity, and keep you updated on progress.
- Fixes are shipped in a new release and disclosed via a GitHub Security Advisory, with a CVE requested where warranted.
- We credit reporters in the advisory by default — tell us if you'd prefer to remain anonymous.
Please give us reasonable time to release a fix before disclosing publicly. We aim to resolve and publish an advisory within 90 days and will coordinate the timing with you.
This policy covers the Faved application code in this repository. Vulnerabilities in third-party dependencies should be reported upstream.