| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability within WrapSplash++, please open a GitHub Issue. All security vulnerabilities will be promptly addressed.
Please do not report security vulnerabilities through public GitHub issues.
When reporting a vulnerability, please include:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 1 week
- Fix release: Depends on severity
When using WrapSplash++:
- Never hardcode credentials in source code
- Use environment variables or secure vaults for API keys
- Enable HTTPS for all API communications
- Validate inputs before processing
- Keep dependencies updated regularly
This security policy applies to:
- The WrapSplash++ library code
- Build system configurations
- CI/CD pipelines
It does not apply to:
- Third-party dependencies (report to their maintainers)
- Applications using WrapSplash++ (report to their maintainers)
For security-related inquiries, please open a GitHub Issue.