40 lines
1.4 KiB
Markdown
40 lines
1.4 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
We currently support the following versions with security updates:
|
|
|
|
| Version | Supported |
|
|
| ------- | ------------------ |
|
|
| 3.4.x | :white_check_mark: |
|
|
| <=3.3 | :x: |
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
Leantime takes security seriously. If you discover a security vulnerability, please follow these steps:
|
|
|
|
1. **Do NOT disclose the vulnerability publicly**
|
|
2. Email security@leantime.io with details about the vulnerability
|
|
3. Allow up to 48 hours for an initial response
|
|
4. Work with us to resolve the issue before any public disclosure
|
|
|
|
For more information, visit our [Responsible Disclosure Policy](https://leantime.io/responsible-disclosure-policy/)
|
|
|
|
## Disclosure Timeframe
|
|
|
|
Once a disclosure has been accepted and fixed in a version we will wait for at least **2** version updates before disclosing to give people enough time to update.
|
|
That means if a vulnerability was discovered in 2.4.1 and then fixed in 2.4.2 it will not be disclosed until we release 2.4.4.
|
|
|
|
## Security Best Practices
|
|
|
|
When deploying Leantime:
|
|
1. Always use Hypertext Transfer Protocol Secure
|
|
2. Keep PHP and all dependencies up to date
|
|
3. Enable two-factor authentication
|
|
4. Use strong passwords
|
|
5. Regular backups
|
|
|
|
## Please refrain from asking for rewards
|
|
|
|
We thank all of you for your dedication to the craft. At this point we cannot offer any monetary rewards for disclosed vulnerabilities.
|