aboutsummaryrefslogtreecommitdiff
path: root/SECURITY.md
blob: 4a30fd7a10691b15eac879d3517ff7121e6d342b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
# Security Policy

## Supported Versions

Currently, all releaswed versions are supported.

| Version            | Supported |
|--------------------|-----------|
| 1.0.0              | ✔️        |
| Any nightly branch | ❌         |
## Reporting a Vulnerability

A vulnerability is currently defined as being able to get the session ID with only a mod that gets loaded after NoSession loads its tweaker.<br>
Vulnerabilities that are out of scope are defined as those that NoSession itself cannot prevent.

However, if you can produce a patch for an out-of-scope vulnerability, a bug bounty will be awarded as well.

The bug bounty is a $5 USD Amazon Gift Card. I might run out, so it's awarded on a first come, first served basis.

Report the bug bounty by sending a DM to PandaNinjas#3017 on Discord.<br>
If you would like, you can encrypt the message with my [public GPG key](https://raw.githubusercontent.com/pandaninjas/pandaninjas/main/pandaninjas-publickey.key)<br>
Your bug bounty may be invalidated if you disclose it to the public before.