Security fixes are provided for the latest released version and the current
main branch.
Older releases may no longer receive security updates.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Report vulnerabilities privately using GitHub Private Vulnerability Reporting.
Please include, when possible:
- The affected SimpleLinuxUpdater version or commit.
- The affected operating system and version.
- Steps required to reproduce the issue.
- The expected and observed behavior.
- The potential security impact.
- A minimal proof of concept, if safe to provide.
- Any suggested remediation.
- Whether the vulnerability is already publicly known.
Remove passwords, SSH private keys, API tokens, server addresses, personal information, and other sensitive values from logs and screenshots before submitting them.
We will review the report privately, investigate its impact, and coordinate a fix and public disclosure when appropriate.
Please allow time for investigation before publishing details publicly.