Skip to content

Security: curiosus-dev/.github

SECURITY.md

Security policy

This policy applies to all curiosus-dev repositories and the Curiosus.* NuGet packages.

Supported versions

Security fixes are released for the latest major version of each package. Older major versions don't get fixes: upgrade to the latest one. The current versions are listed on nuget.org.

The former Curiosity.* and Markeli.TelegramBot packages are no longer maintained, their successors are the Curiosus.* packages.

Reporting a vulnerability

Please don't report vulnerabilities in public issues, discussions or pull requests.

Report privately via GitHub: open the affected repository → Security → Report a vulnerability (how it works).

Please include:

  • the package and version;
  • what an attacker can achieve and under which conditions;
  • steps or a minimal project to reproduce;
  • a suggested fix, if you have one.

What to expect

The projects are maintained by volunteers, so the timelines are best effort:

  • acknowledgement within 7 days;
  • an assessment and, for a confirmed issue, a fix plan within 30 days;
  • a fixed release and a published GitHub security advisory, crediting you unless you prefer otherwise.

Please give us a reasonable time to release a fix before disclosing the issue publicly.

There aren't any published security advisories