2.7 KiB
2.7 KiB
Security Policy
Purpose and Scope
This document defines the security vulnerability reporting, response, and disclosure policy for MokoJoomCommunity. It establishes the authoritative process for responsible disclosure, assessment, remediation, and communication of security issues.
Supported Versions
Security updates are provided for the following versions:
| Version | Supported |
|---|---|
| 01.x.x | ✅ |
| < 01.0 | ❌ |
Only the current major version receives security updates. Users should upgrade to the latest supported version to receive security patches.
Reporting a Vulnerability
Where to Report
DO NOT create public issues for security vulnerabilities.
Report security vulnerabilities privately to:
Email: security@mokoconsulting.tech
Subject Line: [SECURITY] MokoJoomCommunity - Brief Description
What to Include
- Description: Clear explanation of the vulnerability
- Impact: Potential security impact and severity assessment
- Affected Versions: Which versions are vulnerable
- Reproduction Steps: Detailed steps to reproduce the issue
- Proof of Concept: Code, configuration, or demonstration (if applicable)
- Suggested Fix: Proposed remediation (if known)
Response Timeline
- Initial Response: Within 3 business days
- Assessment Complete: Within 7 business days
- Fix Timeline: Depends on severity (Critical: 7 days, High: 14 days, Medium: 30 days, Low: 60 days)
Contact
- Security Team: security@mokoconsulting.tech
- Primary Contact: hello@mokoconsulting.tech
Moko Consulting hello@mokoconsulting.tech