Skip to content

Security: hometrix/SplashMonitor

Security

SECURITY.md

🔒 Política de Seguridad / Security Policy

Splash Monitor — JMGREP Developers / Joan Gregorio Pérez


🇪🇸 Español

Versiones Soportadas

Versión Soporte
1.0.0-beta ✅ Activo

Solo se brinda soporte de seguridad para las versiones listadas. Si utiliza una versión no soportada, actualice a la última versión estable antes de reportar vulnerabilidades.

📢 Reportar una Vulnerabilidad

Si descubre una vulnerabilidad de seguridad en este proyecto, por favor no la haga pública. En su lugar, siga el siguiente proceso de divulgación responsable:

  1. Envíe un correo electrónico al mantenidor del proyecto: joan.gregorio.perez@gmail.com
  2. Asunto del correo: [SECURITY] Vulnerabilidad reportada en Splash Monitor
  3. Espere una respuesta dentro de 48 horas hábiles.

📝 Qué Incluir en el Reporte

Para poder evaluar y resolver el problema eficientemente, incluya:

  • Descripción detallada de la vulnerabilidad
  • Pasos para reproducirla (si aplica)
  • Versión del software afectada
  • Sistema operativo y arquitectura (ej. macOS 13.0+, Apple Silicon)
  • Screenshots o logs relevantes (si es posible)
  • Impacto potencial estimado (confidencialidad, integridad, disponibilidad)
  • Sugerencia de mitigación (opcional, pero apreciado)

⏱️ Expectativas de Respuesta

Fase Tiempo estimado
Confirmación de recepción 48 horas hábiles
Evaluación inicial 5 días hábiles
Corrección o mitigación 30 días hábiles
Divulgación pública Después de la corrección

🛡️ Compromiso del Proyecto

  • No se emprenderán acciones legales contra investigadores que reporten vulnerabilidades de buena fe.
  • Se reconecerá la contribución del investigador (con su consentimiento).
  • Se mantendrá confidencialidad sobre la vulnerabilidad hasta que se resuelva.

🇺🇸 English

Supported Versions

Version Support
1.0.0-beta ✅ Active

Security support is only provided for the listed versions. If you are using an unsupported version, please upgrade to the latest stable release before reporting vulnerabilities.

📢 Reporting a Vulnerability

If you discover a security vulnerability in this project, please do not make it public. Instead, follow this responsible disclosure process:

  1. Send an email to the project maintainer: joan.gregorio.perez@gmail.com
  2. Subject line: [SECURITY] Vulnerability reported in Splash Monitor
  3. Wait for a response within 48 business hours.

📝 What to Include in Your Report

To help us evaluate and resolve the issue efficiently, please include:

  • Detailed description of the vulnerability
  • Steps to reproduce (if applicable)
  • Affected software version
  • Operating system and architecture (e.g., macOS 13.0+, Apple Silicon)
  • Relevant screenshots or logs (if possible)
  • Estimated potential impact (confidentiality, integrity, availability)
  • Suggested mitigation (optional, but appreciated)

⏱️ Response Expectations

Phase Estimated Timeframe
Acknowledgment of receipt 48 business hours
Initial assessment 5 business days
Fix or mitigation 30 business days
Public disclosure After the fix is released

🛡️ Project Commitment

  • No legal action will be taken against researchers who report vulnerabilities in good faith.
  • Researcher credit will be given (with their consent).
  • Confidentiality will be maintained regarding the vulnerability until a fix is released.

📜 Safe Harbor / Refugio Seguro

We consider security research conducted under this policy to be:

  • Authorized under applicable anti-hacking laws
  • Exempt from DMCA restrictions
  • Authorized under this policy's terms

We will not initiate legal action against security researchers for:

  • Accidentally accessing or modifying data that doesn't belong to you
  • Interacting with accounts you own (not others') for testing purposes
  • Avoiding detection or protecting your own research activities
  • Discovering vulnerabilities on our own systems

📞 Contacto / Contact


Last updated / Última actualización: September 2026

There aren't any published security advisories