The Lumina PDF team takes security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings.
You can report security vulnerabilities through our GitHub repository:
- GitHub Security Advisory:
- Navigate to the Security tab in our repository
- Click on "Report a vulnerability"
- Provide a detailed description of the vulnerability
When reporting a vulnerability, please provide:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Any potential impact
- If possible, suggestions for addressing the vulnerability
We aim to acknowledge receipt of your vulnerability report as soon as possible.
- Submit your report through the channel above
- Our team will investigate and validate the issue
- We will work on a fix and keep you updated on our progress
- Once resolved, we will publish the fix and acknowledge your contribution (if desired)
At this time, we do not offer a bug bounty program. However, we greatly appreciate your efforts in making Lumina PDF more secure.
Only the latest version of Lumina PDF is supported for security updates. We do not backport security fixes to older versions.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
Please note: Before reporting a security issue, ensure you are using the latest version of Lumina PDF.
When deploying Lumina PDF:
- Always use the latest version
- Follow our deployment guidelines
- Regularly check for and apply updates