| Version | Supported |
|---|---|
| 1.x.x | ✅ |
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
- Do NOT open a public GitHub issue for security vulnerabilities
- Email the maintainer directly with details about the vulnerability
- Include the following information:
- Type of vulnerability
- Full path of the affected source file(s)
- Location of the affected code (tag/branch/commit or direct URL)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue
- Acknowledgment of your report within 48 hours
- Regular updates on the progress (at least every 7 days)
- Credit for discovering the vulnerability (unless you prefer to remain anonymous)
- Always use the latest version
- Do not expose Vex directly to the public internet without proper authentication
- Use TLS/SSL when deploying in production
- Regularly update your dependencies
When we receive a security bug report, we will:
- Confirm the problem and determine affected versions
- Audit code to find any similar problems
- Prepare fixes for all supported versions
- Release new versions as soon as possible