# Security Policy ## Supported Versions We strongly recommend always using the latest version to benefit from the latest security updates. ## Reporting a Vulnerability We take the security of our software very seriously. If you discover a security vulnerability, please follow these guidelines: ### How to Report Please **DO NOT** create a public issue for security vulnerabilities. Instead, report security vulnerabilities by emailing: 📧 **Email**: `modstart@163.com` ### What to Include When reporting a security vulnerability, please include: 1. **Description**: A clear description of the vulnerability 2. **Steps to Reproduce**: Detailed steps to reproduce the issue 3. **Impact Assessment**: Your assessment of the potential impact 4. **Affected Versions**: Which versions are affected 5. **Proof of Concept**: If applicable, include a PoC or example exploit 6. **Suggested Fix**: If you have ideas on how to fix it (optional) ### Response Process - **Initial Response**: We aim to respond within 48 hours - **Status Updates**: We will keep you informed about the progress - **Disclosure Coordination**: We will coordinate with you on the disclosure timeline - **Credit**: We will credit you in the release notes (unless you prefer to remain anonymous) ### Responsible Disclosure We ask that you: - Give us reasonable time to fix the vulnerability before public disclosure - Avoid exploiting the vulnerability beyond what is necessary to demonstrate it - Do not access, modify, or delete data belonging to others - Do not perform actions that could harm the availability of our services ## Security Updates Security updates will be announced through: - GitHub Releases - Project Documentation - Email notification to users who have reported issues ## Acknowledgments We appreciate the security research community and welcome responsible disclosure of security vulnerabilities.