Security policy

How to report vulnerabilities and security expectations.

Supported versions#

Security fixes are applied to the latest commit on main. Pre-release builds and older commits are not supported.

Reporting a vulnerability#

Please do not open a public issue. Use GitHub's Security → Report a vulnerability flow to submit a private security advisory with:

  • the affected component and commit;
  • reproduction steps or a proof of concept;
  • the expected impact; and
  • any suggested mitigation.

Maintainers aim to acknowledge reports within 3 business days and provide an initial assessment within 7 business days. Timelines for a fix and disclosure depend on severity and complexity. Please allow a reasonable remediation period before public disclosure.

Scope#

Reports about the Rust API and core, the Next.js applications, and the Tauri shells are in scope. Reports about third-party services should be sent to the service owner unless Doso's integration creates the vulnerability.

Never include real personal data, credentials, or production secrets in a report or proof of concept.