Use this section to tell people about which versions of your project are currently being supported with security updates.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability within PepperEvolution, please send an email to mfb@torontomu.ca. All security vulnerabilities will be promptly addressed.
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Initial response: Within 48 hours
- Status update: Within 1 week
- Resolution: As soon as possible, typically within 2-4 weeks
When using PepperEvolution:
- Never commit API keys to version control
- Use environment variables for sensitive configuration
- Keep your Pepper robot in a secure network environment
- Regularly update dependencies
- Monitor logs for suspicious activity
- Use HTTPS for all external communications
- Implement proper authentication if deploying to production
We appreciate security researchers who responsibly disclose vulnerabilities. We will:
- Acknowledge your report
- Work with you to understand and validate the issue
- Keep you updated on our progress
- Credit you in our security advisories (if you wish)
Thank you for helping keep PepperEvolution secure! 🤖🔒