We take the security of Responder and its users seriously.
Security fixes are applied to the latest release and the current main branch.
Older commits and tags are not patched.
Do not report security vulnerabilities through public issues, pull requests, or community chat.
Use GitHub's private vulnerability reporting from the repository Security tab:
https://github.com/superloglabs/responder-oss/security/advisories/new
If that is unavailable, email security@superlog.sh.
Please include the affected component and version, reproduction steps, impact, and a proof of concept when possible. We aim to acknowledge reports within three business days and provide an initial assessment within seven business days. We will coordinate disclosure after a fix is available and credit the reporter unless they prefer otherwise.
This policy covers the code in this repository and the hosted Responder service. Reports from automated scanners should include a demonstrated security impact. Publicly known vulnerable dependencies without an application-specific impact can be reported as a normal dependency update.
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable time to fix an issue before disclosure.