Skip to content

Security: dawiisss/ver

Security

SECURITY.md

Security Policy

Supported Versions

Security updates and patches are actively applied to the following versions of VER:

Version Supported
1.3.x
1.2.x
< 1.2.0

Reporting a Vulnerability

The security of VER and our users' credentials is of paramount importance.

If you discover a security vulnerability or potential credential leak:

  1. Do not disclose it publicly on GitHub issues, pull requests, or discussions.
  2. Please report the vulnerability privately via GitHub Security Advisories.
  3. If GitHub Private Advisories are unavailable, contact the project maintainer directly.

What to Include in Your Report:

  • Description of the vulnerability and its potential security impact.
  • Detailed steps or proof of concept to reproduce the issue.
  • Affected operating system, desktop environment, or protocol connectors (e.g. FreeRDP, TigerVNC, OpenSSH).
  • Any suggested mitigations or fixes.

Response Timeline:

  • Acknowledgment: You will receive an acknowledgment of your report within 48 hours.
  • Assessment & Fix: A patch will be developed, tested, and released promptly.
  • Public Disclosure: Coordinated public disclosure will follow once a patch has been released.

There aren't any published security advisories