This project takes security seriously and strives to follow industry best practices regarding secure software development, dependency management, vulnerability handling, and release management.
The latest released version is actively maintained and receives security updates.
| Version | Supported |
|---|---|
| Latest Release | ✅ |
| Older Releases | ❌ |
If you discover a potential security vulnerability, please report it responsibly.
Please include as much information as possible:
- Description of the issue
- Impact assessment
- Steps to reproduce
- Affected versions
- Proof of concept (if available)
Please do not disclose vulnerabilities publicly before they have been reviewed and addressed.
E-Mail: info@andreas-heine.net
Dependencies are continuously monitored and updated through automated tooling:
- Dependabot
- Renovate
These tools regularly:
- Identify vulnerable dependencies
- Propose dependency upgrades
- Track new security advisories
- Help maintain version currency
The project follows a regular release process.
- Security fixes are included in the next available release.
- Releases are published regularly.
- Dependency and vulnerability updates are continuously integrated.
The project aims to follow secure coding practices including:
- Input validation
- Principle of least privilege
- Secure defaults
- Error handling without information leakage
- Dependency minimization
To reduce software supply chain risks:
- Dependencies are reviewed before adoption.
- Automated dependency update tooling is enabled.
- Security advisories are monitored continuously.
- Unsupported and abandoned libraries are avoided whenever possible.
Production deployments should:
- Use HTTPS/TLS exclusively
- Enforce authentication for protected endpoints
- Implement role-based access control where applicable
- Store credentials securely
- Rotate secrets periodically
Production environments should:
- Run behind a reverse proxy (e.g. NGINX)
- Enable TLS termination
- Enforce authentication and authorization
- Restrict administrative access
- Enable audit logging
- Keep operating systems and containers updated
When a vulnerability is identified:
- Assess severity and impact.
- Validate reproducibility.
- Develop a remediation.
- Validate the fix.
- Publish an updated release.
- Communicate remediation guidance if required.
Security-related updates are delivered through the normal release process.
Users are encouraged to:
- Keep deployments updated
- Regularly review release notes
- Apply updates in a timely manner
While every effort is made to provide a secure implementation, no software can be considered