Skip to content

Security: Bennerdoo/LuminaPDF

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

The Lumina PDF team takes security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings.

How to Report

You can report security vulnerabilities through our GitHub repository:

  1. GitHub Security Advisory:
    • Navigate to the Security tab in our repository
    • Click on "Report a vulnerability"
    • Provide a detailed description of the vulnerability

What to Include

When reporting a vulnerability, please provide:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Any potential impact
  • If possible, suggestions for addressing the vulnerability

Response Time

We aim to acknowledge receipt of your vulnerability report as soon as possible.

Process

  1. Submit your report through the channel above
  2. Our team will investigate and validate the issue
  3. We will work on a fix and keep you updated on our progress
  4. Once resolved, we will publish the fix and acknowledge your contribution (if desired)

Bug Bounty

At this time, we do not offer a bug bounty program. However, we greatly appreciate your efforts in making Lumina PDF more secure.

Supported Versions

Only the latest version of Lumina PDF is supported for security updates. We do not backport security fixes to older versions.

Version Supported
Latest
Older

Please note: Before reporting a security issue, ensure you are using the latest version of Lumina PDF.

Security Best Practices

When deploying Lumina PDF:

  1. Always use the latest version
  2. Follow our deployment guidelines
  3. Regularly check for and apply updates

There aren't any published security advisories