# Security Policy ## Supported Versions The following versions of OxiCloud are currently supported with security updates: | Version | Supported | | ------- | ------------------ | | Latest | :white_check_mark: | ## Reporting a Vulnerability The OxiCloud team takes security issues seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions. To report a security vulnerability, please follow these steps: 1. **DO NOT** disclose the vulnerability publicly (e.g., in GitHub issues) 2. Email details of the vulnerability to the project maintainers 3. Include as much information as possible, such as: - A clear description of the vulnerability - Steps to reproduce the issue - Potential impact - Suggested fixes if available ## What to Expect After submitting a vulnerability report, you can expect the following: 1. **Acknowledgment**: The team will acknowledge receipt of your report within 3 business days 2. **Assessment**: We'll evaluate the vulnerability and determine its impact 3. **Plan**: We'll develop a plan to address the vulnerability 4. **Fix & Release**: Once fixed, we'll release an update 5. **Recognition**: With your permission, we'll acknowledge your contribution in the release notes ## Security Best Practices for OxiCloud Users - Keep your OxiCloud installation updated to the latest version - Use strong, unique passwords for all user accounts - Configure proper file permissions - Regularly back up your data - Consider running OxiCloud behind a reverse proxy with HTTPS - Implement IP restrictions where appropriate Thank you for helping keep OxiCloud and its users secure!