Skip to content

Security: deepakness/optisharp

Security

SECURITY.md

Security Policy

Supported Versions

Currently supported versions for security updates:

Version Supported
1.1

Reporting a Vulnerability

We take the security of this image processing tool seriously. If you discover a security vulnerability, please follow these steps:

  1. Do Not open a public issue for the vulnerability
  2. Send a private email to me@deepakness.com with:
    • A description of the vulnerability
    • Steps to reproduce the issue
    • Possible impacts of the vulnerability
    • Any potential solutions you've identified

What to Expect

After you report a vulnerability:

  1. You'll receive acknowledgment of your report within 48 hours
  2. We'll investigate and provide regular updates on our progress
  3. Once the issue is resolved, we'll publicly acknowledge your responsible disclosure (unless you prefer to remain anonymous)

Security Best Practices

When using this tool:

  1. Always verify input images before processing
  2. Keep Sharp and Node.js updated to their latest stable versions
  3. Run the tool with appropriate user permissions
  4. Be cautious when processing images from untrusted sources
  5. Monitor system resources when processing large batches of images

Dependencies

This project relies on the following major dependencies:

  • Sharp: For image processing
  • Node.js: Runtime environment

We regularly monitor and update these dependencies to patch security vulnerabilities.

There aren’t any published security advisories