Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.
Instead, report them privately through GitHub's private vulnerability reporting:
https://github.com/simukappu/activity_notification/security/advisories/new
This keeps the report private until a fix is available and lets us track it in one place. If you are unable to use that form, you may email the maintainer at shota.yamazaki.work@gmail.com and we will move the discussion into a private advisory.
To help triage and fix the issue quickly, please include as much of the following as you can:
- The affected version(s) or commit, and the specific file or code path involved
- A concrete reproduction or proof of concept
- The impact of the issue and any suggested severity
- Any known workarounds or suggested fixes
This project is maintained on a best-effort basis, and security fixes are applied to the latest released version.
| Version | Supported |
|---|---|
| 2.6.x | Yes |
| < 2.6 | No |
If you rely on an older version, we recommend upgrading to the latest release before reporting, since the fix will be delivered there.
As an open source project maintained in spare time, response times are best-effort rather than guaranteed. In general you can expect:
- An acknowledgement of your report within a few business days
- An initial assessment (accepted, needs more information, or not a vulnerability) after triage
- Coordinated disclosure: we will work with you on a fix and a disclosure timeline, and credit you in the release notes and advisory if you wish
Thank you for helping keep activity_notification and its users safe.