| Version | Supported |
|---|---|
| 0.1.x | ✅ |
We take security seriously. If you discover a security vulnerability, please report it responsibly.
- Do NOT open a public GitHub issue for security vulnerabilities
- Email us at: hi@productdevbook.com
- Include the following information:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Resolution Timeline: Depends on severity, typically within 30 days
- We will acknowledge receipt of your report
- We will investigate and validate the vulnerability
- We will work on a fix and coordinate disclosure timing with you
- We will credit you in the security advisory (unless you prefer to remain anonymous)
When using Devir:
- Keep your
devir.yamlconfiguration file secure - Don't commit sensitive environment variables
- Use the latest version for security updates
- Review service commands before running in production
This security policy applies to:
- The Devir CLI tool
- Official releases on GitHub
- The Homebrew formula
Third-party integrations and forks are outside this scope.