This policy applies to all curiosus-dev repositories and the Curiosus.* NuGet packages.
Security fixes are released for the latest major version of each package. Older major versions don't get fixes: upgrade to the latest one. The current versions are listed on nuget.org.
The former Curiosity.* and Markeli.TelegramBot packages are no longer maintained, their successors are the
Curiosus.* packages.
Please don't report vulnerabilities in public issues, discussions or pull requests.
Report privately via GitHub: open the affected repository → Security → Report a vulnerability (how it works).
Please include:
- the package and version;
- what an attacker can achieve and under which conditions;
- steps or a minimal project to reproduce;
- a suggested fix, if you have one.
The projects are maintained by volunteers, so the timelines are best effort:
- acknowledgement within 7 days;
- an assessment and, for a confirmed issue, a fix plan within 30 days;
- a fixed release and a published GitHub security advisory, crediting you unless you prefer otherwise.
Please give us a reasonable time to release a fix before disclosing the issue publicly.