We release patches for security vulnerabilities. Which versions receive security updates depends on the CVSS v3.0 Rating:
| Version | Supported |
|---|---|
| 0.x.x | ✅ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report security vulnerabilities to security@mindfiredigital.com.
Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:
- Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
- Full paths of source file(s) related to the manifestation of the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit the issue
This information will help us triage your report more quickly.
When we receive a security vulnerability report, we commit to the following process:
- Confirm the problem and determine the affected versions.
- Review the code to find any potential similar issues.
- Prepare fixes for all releases still under maintenance.
- Release new security fix releases as soon as possible.
If you have suggestions on how this process could be improved, please submit them to security@mindfiredigital.com.
Security vulnerabilities are fixed in the following way:
- Critical vulnerabilities (CVSS 9.0-10.0): Emergency patch released immediately
- High vulnerabilities (CVSS 7.0-8.9): Patch released within 1 week
- Medium vulnerabilities (CVSS 4.0-6.9): Patch released within 2 weeks
- Low vulnerabilities (CVSS 0.1-3.9): Fixed in next regular release
- Keep gpx and its dependencies up to date
- Review dependency security advisories regularly
- Use package locks in version control
Thank you for helping keep gpx and our users safe!
Humans responsible for security can be reached at security@mindfiredigital.com