At ZenYukti, we take security seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.
-
Submit Report: Send details of the vulnerability to info@zenyukti.in with the subject line "[SECURITY] Vulnerability Report".
-
Encryption: For sensitive reports, you can encrypt your message using our PGP key (available upon request).
-
Information to Include:
- Description of the vulnerability
- Steps to reproduce
- Affected versions/components
- Potential impact
- Any suggested mitigation or fix (if available)
- Your contact information for follow-up (optional)
- Acknowledgment: We'll acknowledge receipt of your report within 48 hours.
- Updates: We'll provide regular updates about our progress in addressing the issue.
- Resolution: Once resolved, we'll notify you and discuss appropriate disclosure timing.
- Recognition: With your permission, we'll acknowledge your contribution in our release notes and security advisories.
| Project | Version | Supported |
|---|---|---|
| Core | 1.x | ✅ |
| < 1.0 | ❌ | |
| Web App | 2.x | ✅ |
| 1.x | ✅ | |
| < 1.0 | ❌ |
- Security issues are prioritized over feature development.
- Critical vulnerabilities receive patches for all supported versions.
- Security updates are clearly marked in release notes.
- We aim to release security patches within:
- Critical: 7 days
- High: 14 days
- Medium/Low: Next scheduled release
- Dependency Management: Regularly update dependencies and check for security advisories.
- Code Reviews: Security-focused code reviews are required for authentication, authorization, and data handling.
- Secure Development: Follow OWASP guidelines for secure coding practices.
- Testing: Include security-focused tests when applicable.
ZenYukti implements several security measures across our projects:
- Regular dependency scanning and updates
- Static code analysis in our CI/CD pipeline
- Input validation and output encoding
- Content Security Policy implementation
- Regular security training for core contributors
We believe in responsible disclosure:
- Security issues are disclosed after a patch is available
- We provide users adequate time to update before full details are published
- Proof-of-concept code is never released if it could harm users
- We coordinate disclosure with affected dependency maintainers when applicable
We'd like to thank the following individuals for responsibly reporting security issues:
(This section will be updated as contributions are received)
Thank you for helping keep ZenYukti and our community safe!
Contact: support@zenyukti.in
Discord: ZenYukti Community
Website: https://zenyukti.in
X (Twitter): https://x.com/zenyukti
LinkedIn: https://linkedin.com/company/zenyukti