The following versions of Nero are currently supported with security updates:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
If you discover a security vulnerability within Nero, please send an email to security@nero.ai. All security vulnerabilities will be promptly addressed.
Please include the following information:
- Type of vulnerability
- Full paths of source file(s) related to the vulnerability
- Location of the affected source code (tag/branch/commit or direct URL)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
We aim to acknowledge vulnerability reports within 48 hours and provide a more detailed response within 7 days. We will work with you to understand and address the vulnerability promptly.
Security updates will be released as patch versions and announced through the project's GitHub repository.
We follow a coordinated disclosure practice. We request that you give us reasonable time to address the vulnerability before disclosing it publicly.
Nero uses third-party dependencies. If a vulnerability is discovered in a dependency, we will monitor security advisories and update dependencies as needed.
When contributing to Nero:
- Never hardcode API keys, passwords, or secrets in the codebase
- Use environment variables or secure storage for sensitive configuration
- Follow Flutter/Dart security best practices
- Sanitize user inputs before processing
For security-related concerns, please contact: security@nero.ai