We maintain security updates for the following versions:
Version | Supported |
---|---|
main | ✅ |
If you discover a security vulnerability within YeonSphere projects, please follow these steps:
- DO NOT disclose the vulnerability publicly
- Send a detailed report to daedaevibin@naver.com
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Initial Response: Within 24 hours
- Status Update: Within 72 hours
- Resolution Timeline: Within 30 days
- Regular security audits
- Automated vulnerability scanning
- Dependency updates via Dependabot
- Code scanning with CodeQL
- OWASP ZAP scanning
We follow these security best practices:
- Regular dependency updates
- Code review requirements
- Automated security testing
- Content Security Policy implementation
- HTTPS enforcement
- Regular backups
Security Contact: daedaevibin@naver.com GitHub: @daedaevibin