| Version | Supported |
|---|---|
| 1.0.2 | ✅ |
| 1.0.1 | ✅ |
| 1.0.0 | ❌ |
If you discover a security vulnerability in this project, please report it by creating an issue with the "security" label. You can also contact the maintainers directly via email.
Please include the following information in your report:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if possible)
This project takes security seriously and implements the following security measures:
- Regular Dependency Updates: We use Dependabot to keep dependencies up-to-date and address security vulnerabilities.
- Automated Vulnerability Scanning: The project uses OWASP Dependency-Check in CI workflows to identify vulnerable dependencies.
- Code Reviews: All changes undergo code review before being merged.
We aim to address critical security vulnerabilities promptly. Updates will be released as follows:
- Critical Issues: Within 7 days
- High Severity Issues: Within 14 days
- Moderate/Low Severity Issues: Within 30 days
When using this tool:
- Always use the latest version
- Be cautious when processing untrusted input files
- Run with appropriate permissions (don't run as root/admin)