Skip to content

Security: seanpm2001/SeansAudioDB

Security

SECURITY.md


Security Policy

Supported Versions

Click/tap here to expand/collapse this section

This project is still in its early stages, although the only functional part is essentially a web application, or a set of media files. It is written in HTML5, jQuery, and a tiny bit of CSS, so it shouldn't be too much of a problem (I chose jQuery for one feature I was trying out, but it still didn't work the way I wanted it to, but I kept it in anyways, I was trying to make a popup about page)

For general security vulnerabilities, use the security label and start your issue title with [SECURITY]. Remember to not publicly post critical/zero day vulnerabilities, see more on this below.

Version history

Click/tap here to expand/collapse this section

Version Supported? Support status
V0.0.1 Old version, not supported
V0.0.2 Old version, not supported
V0.0.3 Old version, not supported
V0.0.4 Old version, not supported
V0.0.5 Old version, not supported
V0.0.6 Old version, not supported
V0.0.7 Old version, not supported
V0.0.8 Old version, not supported
V0.0.9 Old version, not supported
V0.0.10 Old version, not supported
V0.0.11 Old version, not supported
V0.0.12 Old version, not supported
V0.0.13 Old version, not supported
V0.0.14 Old version, not supported
V0.0.15 Old version, not supported
V0.0.16 Old version, not supported
V0.0.17 Old version, not supported
V0.0.18 Old version, not supported
V0.0.19 Old version, not supported
V0.0.20 Old version, not supported
V0.0.21 Old version, not supported
V0.0.22 Old version, not supported
V0.0.23 Old version, not supported
V0.0.24 Old version, not supported
V0.0.25 Old version, not supported
V0.1.0 Old version, not supported
V0.1.1 Old version, not supported
V0.1.2 Current version, supported
> V0.1.1 & > 2021 October 27th Current version set, supported
V0.1.3 NOT YET RELEASED

Reporting a Vulnerability

Click/tap here to expand/collapse this section

DO NOT REPORT A ZERO DAY VULNERABILITY PUBLICLY!

Please instead direct message me via GitHub. If there is no response within 90 days, you can post the vulnerability as an issue, as part of the standard 0 day security exploit reporting guidelines.

If a vulnerability is caused by an outdated dependancy, you can report it publicly, as it usually isn't that much of a problem.

Dependencies

Click/tap here to expand/collapse this section

Dependency problems aren't very bad. This project uses 5 different languages:

  • HTML5

  • CSS3

  • JQuery

  • JSON

  • Shell (BASH)

You can still report dependency problems, but dependencies usually won't be updated unless they get too old (5+ years before the most recent release) or they aren't common enough to download anymore. The current dependencies this project has include:

  • JSON ? (the program will work with any stable version of JSON)

  • Python 3.7.2 (although the program will still run with any version of Python prior to Python 3.0)

  • CSS 3.0 (although the program will still run with any version of CSS prior to CSS 2.0 as of 2021 October 28th at 8:00 pm)

  • jQuery 1.9.1 (I am unsure whether bumping the version up or down will cause problems)

  • BASH shell 5.0 (althouh the program will still run with any version of BASH shell from 3.0 or higher, and it can also be bumped up if needed)

Other

Click/tap here to expand/collapse this section

Other security info currently isn't available. If there are any further questions, @ me privately on GitHub. @seanpm2001


File info

Click/tap here to expand/collapse this section

File type: Markdown document (*.md *.mkd *.mdown *.markdown)

File purpose: Lying out the security policy for this project.

File version: 1 (2021, Thursday, October 28th at 8:03 pm)

File language: English (US)

Line count (including blank lines and compiler line): 164

All times are UTC-7 (PDT/Pacific Time)

You may need special rendering support for the <dropdown> HTML tag being used in this document

Encoding: UTF-8 (with no non-US-ASCII characters)


File history

Click/tap here to expand/collapse the history for this file

Version 1 (2021, Thursday, October 28th at 8:03 pm)

Changes:

  • Started the file
  • Added the supported versions section
  • Added the version history section
  • Added the reporting a vulnerability section
  • Added the file info section
  • Added the file history section
  • No other changes in version 1

Version 2 (Coming soon)

Changes:

  • Coming soon
  • No other changes in version 2

There aren’t any published security advisories