65 lines
1.4 KiB
Markdown
65 lines
1.4 KiB
Markdown
# 🔐 Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
Security updates are provided for the actively maintained versions of
|
|
**ComfyUI_PromptManager**.
|
|
|
|
| Version | Supported |
|
|
|-----------------|-----------|
|
|
| `main` / latest | ✅ |
|
|
| Older releases | ❌ |
|
|
|
|
Users are encouraged to stay up to date with the latest version.
|
|
|
|
---
|
|
|
|
## Reporting a Vulnerability
|
|
|
|
For most security-related issues, **please open a GitHub issue** in this
|
|
repository.
|
|
|
|
When opening an issue:
|
|
- Clearly describe the problem
|
|
- Include steps to reproduce
|
|
- Mention the affected version or commit
|
|
- Avoid posting secrets, tokens, or private data
|
|
|
|
### Sensitive Issues
|
|
|
|
If you believe the issue:
|
|
- Could enable remote code execution
|
|
- Exposes credentials or private data
|
|
- Is actively exploitable in the wild
|
|
|
|
Please use **GitHub Security Advisories** instead:
|
|
- Go to the **Security** tab
|
|
- Click **Report a vulnerability**
|
|
|
|
---
|
|
|
|
## Response Expectations
|
|
|
|
- Issues are typically reviewed within **a few days**
|
|
- Valid issues will be labeled and tracked publicly
|
|
- Fixes may be discussed openly and merged transparently
|
|
|
|
---
|
|
|
|
## Scope
|
|
|
|
This policy applies to:
|
|
- Code contained in this repository
|
|
- Default configurations and documented usage
|
|
|
|
It does not cover:
|
|
- Third-party nodes, models, or extensions
|
|
- User workflows, prompts, or local environment issues
|
|
|
|
---
|
|
|
|
## Thank You
|
|
|
|
Community reports and transparency help keep the project healthy.
|
|
Thanks for contributing responsibly.
|