Skip to content

Security: diveprotocol/dive-tools

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in DIVE Tools, please report it responsibly.

  • Email: mateo@callec.net
  • Include a clear description of the issue, steps to reproduce, and any relevant logs or screenshots.
  • Please avoid public disclosure until the issue has been addressed.

Supported Versions

  • 1.0.0 – initial release

Security fixes will be backported to all supported versions as necessary.

Security Best Practices

  • Keep dependencies up to date.
  • Run the API behind HTTPS.
  • Use a strong SECRET_KEY in .env.
  • Validate URLs carefully before processing.

Response

  • We aim to acknowledge security reports within 48 hours.
  • Critical vulnerabilities will be addressed promptly, with patches released as needed.

There aren’t any published security advisories