Skip to content

Security: izored/OpenMemo

Security

SECURITY.md

Security Policy

Supported Versions

openMemo ships from a single line. The newest release is the supported one, and fixes land there rather than being backported.

Version Supported
3.13.x
< 3.13

If you are running an older build, update before reporting: the answer to most reports on a stale version is a release that already fixed it.

Reporting a Vulnerability

If you discover a security vulnerability in OpenMemo, please report it responsibly.

Please do NOT open a public GitHub issue for security bugs.

Instead, email us at dev@izo.red with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

We will acknowledge receipt within 48 hours and aim to provide a fix within 14 days.

Disclosure Policy

  • We will investigate all reports promptly.
  • We will coordinate a fix and release before any public disclosure.
  • We will credit reporters who wish to be named in the release notes.
  • We ask that reporters give us reasonable time to fix before disclosing publicly.

There aren't any published security advisories