Splash Monitor — JMGREP Developers / Joan Gregorio Pérez
| Versión | Soporte |
|---|---|
| 1.0.0-beta | ✅ Activo |
Solo se brinda soporte de seguridad para las versiones listadas. Si utiliza una versión no soportada, actualice a la última versión estable antes de reportar vulnerabilidades.
Si descubre una vulnerabilidad de seguridad en este proyecto, por favor no la haga pública. En su lugar, siga el siguiente proceso de divulgación responsable:
- Envíe un correo electrónico al mantenidor del proyecto: joan.gregorio.perez@gmail.com
- Asunto del correo:
[SECURITY] Vulnerabilidad reportada en Splash Monitor - Espere una respuesta dentro de 48 horas hábiles.
Para poder evaluar y resolver el problema eficientemente, incluya:
- Descripción detallada de la vulnerabilidad
- Pasos para reproducirla (si aplica)
- Versión del software afectada
- Sistema operativo y arquitectura (ej. macOS 13.0+, Apple Silicon)
- Screenshots o logs relevantes (si es posible)
- Impacto potencial estimado (confidencialidad, integridad, disponibilidad)
- Sugerencia de mitigación (opcional, pero apreciado)
| Fase | Tiempo estimado |
|---|---|
| Confirmación de recepción | 48 horas hábiles |
| Evaluación inicial | 5 días hábiles |
| Corrección o mitigación | 30 días hábiles |
| Divulgación pública | Después de la corrección |
- No se emprenderán acciones legales contra investigadores que reporten vulnerabilidades de buena fe.
- Se reconecerá la contribución del investigador (con su consentimiento).
- Se mantendrá confidencialidad sobre la vulnerabilidad hasta que se resuelva.
| Version | Support |
|---|---|
| 1.0.0-beta | ✅ Active |
Security support is only provided for the listed versions. If you are using an unsupported version, please upgrade to the latest stable release before reporting vulnerabilities.
If you discover a security vulnerability in this project, please do not make it public. Instead, follow this responsible disclosure process:
- Send an email to the project maintainer: joan.gregorio.perez@gmail.com
- Subject line:
[SECURITY] Vulnerability reported in Splash Monitor - Wait for a response within 48 business hours.
To help us evaluate and resolve the issue efficiently, please include:
- Detailed description of the vulnerability
- Steps to reproduce (if applicable)
- Affected software version
- Operating system and architecture (e.g., macOS 13.0+, Apple Silicon)
- Relevant screenshots or logs (if possible)
- Estimated potential impact (confidentiality, integrity, availability)
- Suggested mitigation (optional, but appreciated)
| Phase | Estimated Timeframe |
|---|---|
| Acknowledgment of receipt | 48 business hours |
| Initial assessment | 5 business days |
| Fix or mitigation | 30 business days |
| Public disclosure | After the fix is released |
- No legal action will be taken against researchers who report vulnerabilities in good faith.
- Researcher credit will be given (with their consent).
- Confidentiality will be maintained regarding the vulnerability until a fix is released.
We consider security research conducted under this policy to be:
- Authorized under applicable anti-hacking laws
- Exempt from DMCA restrictions
- Authorized under this policy's terms
We will not initiate legal action against security researchers for:
- Accidentally accessing or modifying data that doesn't belong to you
- Interacting with accounts you own (not others') for testing purposes
- Avoiding detection or protecting your own research activities
- Discovering vulnerabilities on our own systems
- Email: joan.gregorio.perez@gmail.com
- GitHub: hometrix/SplashMonitor
- Maintainer: Joan Gregorio Pérez — JMGREP Developers
Last updated / Última actualización: September 2026