Security policy
How to report vulnerabilities and security expectations.
Supported versions#
Security fixes are applied to the latest commit on main. Pre-release builds
and older commits are not supported.
Reporting a vulnerability#
Please do not open a public issue. Use GitHub's Security → Report a vulnerability flow to submit a private security advisory with:
- the affected component and commit;
- reproduction steps or a proof of concept;
- the expected impact; and
- any suggested mitigation.
Maintainers aim to acknowledge reports within 3 business days and provide an initial assessment within 7 business days. Timelines for a fix and disclosure depend on severity and complexity. Please allow a reasonable remediation period before public disclosure.
Scope#
Reports about the Rust API and core, the Next.js applications, and the Tauri shells are in scope. Reports about third-party services should be sent to the service owner unless Doso's integration creates the vulnerability.
Never include real personal data, credentials, or production secrets in a report or proof of concept.