The following versions of eMDeck are actively supported with security updates:
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in eMDeck, please follow these steps to report it:
-
Email the Security Team: Send an email to security@yourdomain.com with the following details:
- A detailed description of the vulnerability.
- Steps to reproduce the issue.
- Any potential impact of the vulnerability.
- Optionally, suggestions for fixing the issue.
-
Do Not Disclose Publicly:
- Please do not disclose the vulnerability until we have had a chance to investigate and release a fix.
-
Acknowledgment:
- We will acknowledge receipt of your email within 48 hours.
- We aim to provide an initial response, including a timeline for remediation, within 7 days.
-
Responsible Disclosure:
- Once the vulnerability is resolved, we will release an advisory with proper credit to the discoverer, unless they wish to remain anonymous.
-
Patch Release:
- Security patches will be backported to all supported versions.
-
Advisory Publication:
- A public advisory will be issued via the repository's Security Advisory page.
To ensure your deployment of eMDeck is secure:
- Keep Dependencies Updated:
- Regularly update Docker images, Ruby gems, and Node.js dependencies.
- Use Secure Configuration:
- Follow the deployment guidelines in the
README.md.
- Follow the deployment guidelines in the
- Limit Access:
- Restrict access to services like MySQL, Redis, and Nginx to trusted IPs.
- Monitor Logs:
- Regularly review logs to detect unusual activity.
Thank you for helping to make eMDeck secure for everyone!