Skip to content

Security: bala2006/nero

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of Nero are currently supported with security updates:

Version Supported
1.0.x

Reporting a Vulnerability

If you discover a security vulnerability within Nero, please send an email to security@nero.ai. All security vulnerabilities will be promptly addressed.

Please include the following information:

  • Type of vulnerability
  • Full paths of source file(s) related to the vulnerability
  • Location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

Response Timeline

We aim to acknowledge vulnerability reports within 48 hours and provide a more detailed response within 7 days. We will work with you to understand and address the vulnerability promptly.

Security Updates

Security updates will be released as patch versions and announced through the project's GitHub repository.

Disclosure Policy

We follow a coordinated disclosure practice. We request that you give us reasonable time to address the vulnerability before disclosing it publicly.

Third-Party Dependencies

Nero uses third-party dependencies. If a vulnerability is discovered in a dependency, we will monitor security advisories and update dependencies as needed.

Security Best Practices

When contributing to Nero:

  • Never hardcode API keys, passwords, or secrets in the codebase
  • Use environment variables or secure storage for sensitive configuration
  • Follow Flutter/Dart security best practices
  • Sanitize user inputs before processing

Contact

For security-related concerns, please contact: security@nero.ai

There aren't any published security advisories