Security Policy
Supported versions and the private GitHub channel for reporting a vulnerability.
NasDash SECURITY.md supports the latest published 0.1.x release and main. The deleted v1.0.0 tag is not a supported version.
| Version | Support status |
|---|---|
Current main branch | supported |
Latest published 0.1.x release | supported |
| Older releases | best effort; an upgrade may be required |
| Third-party forks or unofficial images | not supported |
Reporting a vulnerability
Use the GitHub private advisory form. Do not contact the maintainer by personal email.
If private reporting is not available, open a minimal issue asking for a private contact channel. Do not include exploit code, credentials, tokens, private URLs, configuration files or other sensitive details in a public issue.
Include, when possible:
- the affected NasDash version, image tag or commit;
- the deployment method and relevant environment details;
- clear reproduction steps and the security impact;
- sanitized logs, requests or a minimal proof of concept.
You should receive an acknowledgement within seven days and an initial assessment within fourteen days.
Do not test a vulnerability against an instance you do not own or without explicit authorization.
The reference text remains SECURITY.md.