Skip to content

Security: Arean-Max/synchro-nova

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release branch is currently supported for security updates.

Version Supported
2.2.x ✅
< 2.2.0 ❌

Reporting a Vulnerability

If you discover a security vulnerability in Synchro Nova, please report it responsibly.

How to Report

  1. GitHub Security Advisory: Submit a report via the Security Advisories tab. This creates a private disclosure channel directly with the maintainers.

  2. Direct Contact: Alternatively, contact the project maintainer via GitHub profile: @Arean-Max.

What to Include

To help us triage and reproduce the issue quickly, please include:

  • Affected version or commit hash.
  • Step-by-step reproduction instructions.
  • Potential security impact (e.g., local privilege escalation, unexpected registry write, path traversal).
  • Proposed fix or mitigation, if available.

Disclosure Policy

  • Security reports are triaged within 48 hours of receipt.
  • Fixes will be prepared and released promptly before public disclosure.

There aren't any published security advisories