2020-06-11 11:34:12 +07:00
|
|
|
# Security Policy
|
|
|
|
|
|
|
|
This project makes heavy use of `eval` and similar concepts.
|
|
|
|
|
2020-08-12 12:27:28 +07:00
|
|
|
Queries are not meant to come from untrusted sources. My advice is to never run
|
|
|
|
this as an online service.
|
2020-06-11 11:34:12 +07:00
|
|
|
|
|
|
|
## Supported Versions
|
|
|
|
|
|
|
|
Only the latest release is supported. I will not backport fixes.
|
|
|
|
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
|
2020-08-12 12:27:28 +07:00
|
|
|
For vulnerabilities that do not require a compromised user account:
|
|
|
|
|
|
|
|
contact me at tiposchi@tiscali.it
|
2020-06-11 11:34:12 +07:00
|
|
|
|
|
|
|
My PGP key is on this file, on git.
|
|
|
|
debian/upstream/signing-key.asc
|