48 lines
1.3 KiB
Markdown
48 lines
1.3 KiB
Markdown
# Security Policy
|
|
|
|
## Supported Versions
|
|
|
|
Security updates are provided for the latest release version of evcc.
|
|
|
|
| Version | Supported |
|
|
| ------- | ------------------ |
|
|
| latest | :white_check_mark: |
|
|
| < latest| :x: |
|
|
|
|
## Reporting Vulnerabilities
|
|
|
|
To report a security vulnerability:
|
|
|
|
1. **DO NOT** create a public GitHub issue
|
|
2. Send details to the maintainers:
|
|
- via E-Mail: info@evcc.io
|
|
- via Slack: https://evcc.io/slack (DM to `andig`, `naltatis` or `premultiply`)
|
|
- via GitHub Security Advisory: https://github.com/evcc-io/evcc/security/advisories/new
|
|
|
|
Include in your report:
|
|
- Description of the vulnerability
|
|
- Steps to reproduce
|
|
- Affected versions
|
|
- Potential impact
|
|
|
|
## Response Timeline
|
|
|
|
We are an open source project and not full-time maintainers.
|
|
While we take security seriously and will do our best to respond quickly, we cannot guarantee specific response times.
|
|
|
|
- We aim to acknowledge reports as soon as possible
|
|
- Updates will be provided as we investigate
|
|
- Resolution time depends on severity and complexity
|
|
|
|
## Scope
|
|
|
|
In scope:
|
|
- evcc core application
|
|
- official Docker images
|
|
- configuration security
|
|
- API endpoints
|
|
|
|
Out of scope:
|
|
- third-party integrations (e.g. Home Assistant Addon)
|
|
- user configurations
|
|
- hardware devices
|