Skip to content

Security: R1355201/RVG

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of Rvg are currently receiving security updates:

Version Supported
latest
< latest

Update this table with real version numbers once you have official releases (e.g. 1.x, 2.x).

Reporting a Vulnerability

If you discover a security vulnerability in Rvg, please do not open a public GitHub issue.

Instead, report it privately through the following channel:

Please contact us directly and privately via Telegram rather than posting details publicly.

Please include as much of the following information as possible:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue (proof-of-concept code, if available)
  • The version/commit of Rvg affected
  • Any suggested fix or mitigation, if you have one

Response Process

  • We aim to acknowledge new reports within 48–72 hours.
  • We will investigate and confirm the issue, then work on a fix.
  • Once a fix is ready, we will coordinate a release and, if appropriate, publish a security advisory.
  • We ask that you give us a reasonable amount of time to address the issue before disclosing it publicly (responsible disclosure).

Scope

This policy covers the Rvg source code in this repository. Issues in third-party dependencies should be reported to their respective maintainers, though we appreciate being notified as well.

Recognition

We're happy to credit security researchers who responsibly report valid vulnerabilities, unless they prefer to remain anonymous.


Thank you for helping keep Rvg and its users safe.

There aren't any published security advisories