Skip to content

Security: tunnetio/Tunnet

SECURITY.md

Security Policy

Supported Versions

Tunnet is currently pre-1.0 and evolves quickly. Security updates are provided only for the latest released version.

Older releases are not maintained or backported with security fixes. Users should upgrade to the latest release before reporting or evaluating a security issue.

This policy will change once Tunnet reaches a stable 1.0 release.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report vulnerabilities privately through GitHub's Private Vulnerability Reporting for the Tunnet repository.

When reporting a vulnerability, include as much of the following as possible:

  • A description of the vulnerability and its potential impact.
  • The affected component or code path.
  • Steps or a proof of concept to reproduce the issue.
  • The Tunnet version or commit tested.
  • Any known mitigations or suggested fixes.

We will review reports as soon as reasonably possible and keep reporters informed of significant progress.

If the issue is confirmed, we will work on a fix and coordinate disclosure where appropriate. If the report is determined not to be a security vulnerability, we will explain why.

Please avoid publicly disclosing a vulnerability before a fix is available.

There aren't any published security advisories