Skip to content

Security: serververs/network-transit

Security

SECURITY.md

Security Policy

Supported Versions

We actively maintain and provide security updates for the following versions of Serververse™ Network Transit:

Version Supported
v0.1.x ✅ Supported
< v0.1.0 ❌ Not Supported

Users are strongly advised to always use the latest stable release via: https://transit.serververs.com/transit.sh


Reporting a Vulnerability

We take security seriously. If you discover a vulnerability in Serververse™ Network Transit, please report it responsibly.

How to Report

Please include:

  • Detailed description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (if available)

Response Timeline

  • Initial response: within 24–72 hours
  • Status updates: provided as investigation progresses
  • Resolution time: depends on severity and complexity

Disclosure Policy

  • Do not publicly disclose vulnerabilities before they are resolved
  • We will notify you once a fix is deployed
  • Coordinated disclosure is encouraged

Scope

This policy applies to:

  • The transit.sh installer and related scripts
  • Configuration generation and networking logic
  • Deployment workflows and automation behavior

Out of Scope

  • Issues caused by user misconfiguration
  • Unsupported or modified versions
  • Third-party dependencies outside our control

Acknowledgement

We appreciate responsible disclosure and may acknowledge contributors who help improve the security of Serververse™.

There aren’t any published security advisories