Thank you for helping keep Nexment secure.
The security of our users and projects is a top priority. If you discover a potential security vulnerability in any public Nexment project, we encourage you to report it responsibly.
Security updates are provided for the latest stable release of each public Nexment project.
Projects or versions that are no longer actively maintained may not receive security updates.
Please do not report security vulnerabilities through public GitHub issues or discussions.
Instead, report them privately by emailing:
To help us investigate efficiently, please include:
- The affected project and version
- A clear description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any proof of concept or supporting information (if applicable)
The more information you provide, the faster we can investigate.
After receiving your report, we will:
- Acknowledge your report within 7 days
- Investigate and verify the issue
- Keep you informed of significant progress whenever possible
- Work to resolve confirmed vulnerabilities as quickly as reasonably possible
Every report is reviewed carefully.
To help protect users, we ask that you:
- Keep vulnerability details private until a fix has been released or we approve public disclosure.
- Give us reasonable time to investigate and resolve the issue.
- Avoid sharing exploit details publicly before the issue has been addressed.
Responsible disclosure helps protect everyone using Nexment projects.
Security research is welcome when conducted responsibly.
Examples of acceptable activities include:
- Reviewing source code
- Testing your own local installations
- Performing static analysis
- Reporting vulnerabilities in good faith
The following activities are not permitted:
- Attacking production infrastructure
- Denial-of-service (DoS) attacks
- Social engineering
- Accessing, modifying, or deleting data that does not belong to you
- Any activity that disrupts services or negatively affects other users
Nexment does not currently operate a bug bounty program.
If your report identifies a previously unknown, valid security vulnerability, you will receive full public credit for your discovery unless you request to remain anonymous.
Verified researchers may also be recognized in future security acknowledgements or release notes.
This policy applies to all public repositories and projects maintained under the Nexment organization unless a repository provides its own security policy.
If you have any questions regarding security or responsible disclosure, please contact:
Thank you for helping make Nexment safer for everyone.