Skip to content

Security: Run-Panel/VerTree

Security

SECURITY.md

Security Policy

Supported Versions

We actively support the following versions of VerTree:

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

We take the security of VerTree seriously. If you discover a security vulnerability, please follow these steps:

  1. Do not open a public issue for the vulnerability
  2. Email us at security@vertree.dev with details of the vulnerability
  3. Include as much information as possible:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes

What to Expect

  • Acknowledgment: We'll acknowledge receipt of your report within 48 hours
  • Investigation: We'll investigate and validate the issue within 5 business days
  • Resolution: We'll work to fix the issue and release a patch as soon as possible
  • Disclosure: We'll coordinate with you on the disclosure timeline

Responsible Disclosure

We follow responsible disclosure practices:

  • We'll keep you informed throughout the process
  • We'll credit you for the discovery (unless you prefer to remain anonymous)
  • We'll notify users of security updates through our normal channels

Security Best Practices

When deploying VerTree:

  1. Always use HTTPS in production
  2. Keep your Go runtime and dependencies up to date
  3. Use strong authentication credentials
  4. Regularly update to the latest version
  5. Monitor your deployment for unusual activity
  6. Follow the principle of least privilege for database access

Contact

For security-related questions: security@vertree.dev

There aren’t any published security advisories