Skip to content

Security: divmora/functionless-url-shortener

Security

SECURITY.md

Security Policy

The DIVMORA Technologies team takes the security of our software and users seriously. We appreciate responsible disclosure of security vulnerabilities and are committed to addressing them promptly.


Supported Versions

Only the latest release branch of Functionless URL Shortener receives active security patches.

Version Supported
0.1.x
< 0.1

Reporting a Vulnerability

Important

Please do not report security vulnerabilities via public GitHub issues, discussions, or pull requests.

If you discover a security vulnerability, please report it through one of the following private channels:

  1. Email: Send an encrypted or direct email to security@divmora.com.
  2. GitHub Security Advisory: Submit a private vulnerability report directly via the repository's Security tab -> Report a vulnerability.

What to Include in Your Report

To help us investigate and reproduce the issue efficiently, please include:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions or a minimal proof-of-concept (PoC) to reproduce the vulnerability.
  • Affected component(s), versions, and operating environment / AWS configuration.
  • Any suggested mitigations or patches (if available).

Response & Disclosure Process

  1. Acknowledgement: Our security team will acknowledge receipt of your report within 48 hours.
  2. Triage & Assessment: We will investigate and confirm the issue, keeping you informed of our progress.
  3. Fix & Validation: A fix will be developed and tested across affected environments.
  4. Coordinated Disclosure: We will coordinate the release of the patch along with a security advisory crediting you for the responsible discovery (if desired).

There aren't any published security advisories