Skip to content

Latest commit

 

History

History
90 lines (60 loc) · 2.95 KB

File metadata and controls

90 lines (60 loc) · 2.95 KB

Security Policy

Supported Versions

The following versions of ViewTouch are currently supported with security updates:

Version Supported Notes
26.01.x Current stable release
< 26.01 End of life

Note: Only the latest stable release receives security updates. For the latest version information, please check the project repository.

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security vulnerability in ViewTouch, please report it responsibly.

How to Report

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by:

  1. Email: Send details to gene@viewtouch.com
  2. Phone: Call 541-515-5913 (Gene Mosher)
  3. GitHub Security Advisories: Use GitHub's private vulnerability reporting feature if available

What to Include

When reporting a vulnerability, please include:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact and severity
  • Any suggested fixes or mitigations
  • Your contact information for follow-up

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution: Depends on severity and complexity

Vulnerability Disclosure Policy

We follow responsible disclosure practices:

  1. Confidentiality: We will keep your report confidential until a fix is available
  2. Coordination: We will work with you to coordinate public disclosure
  3. Credit: We will credit you for the discovery (unless you prefer to remain anonymous)
  4. No Legal Action: We will not pursue legal action against security researchers who act in good faith

Security Best Practices

For Users

  • Keep ViewTouch updated to the latest supported version
  • Use strong passwords for all user accounts
  • Regularly review and audit user permissions
  • Monitor system logs for suspicious activity
  • Keep the underlying operating system updated
  • Use secure network configurations

For Developers

  • Follow secure coding practices
  • Validate all user inputs
  • Use parameterized queries for database operations
  • Implement proper authentication and authorization
  • Keep dependencies updated
  • Conduct regular security reviews

Security Updates

Security updates will be released as soon as possible after a vulnerability is confirmed and a fix is developed. Updates will be:

  • Announced on the ViewTouch website
  • Available through the standard update channels
  • Documented in release notes with appropriate detail

Contact Information

Acknowledgments

We appreciate the security research community and responsible disclosure practices. Thank you for helping keep ViewTouch secure.