Skip to content

Security: miralabs-tech/standardoc

SECURITY.md

Security Policy

📖 English · Français

Supported Versions

Security updates are currently provided only for the latest supported beta release.

Version Supported
1.x beta
< 1.0.0

Older versions may contain known vulnerabilities, protocol incompatibilities, or outdated dependencies and are no longer maintained.


Official Distribution

Official Standardoc binaries are distributed only through official project channels maintained by miralabs-tech.

Official sources:

Official distributions may include:

  • standalone CLI binaries
  • platform-specific archives
  • binaries bundled with official editor extensions
  • structured version manifests
  • SHA256 checksums

Do NOT trust binaries, installers, mirrors, forks, reuploads, or third-party redistributions claiming to be Standardoc.

Unofficial distributions may be modified, outdated, unsafe, or malicious.

Standardoc does NOT officially distribute:

  • generic "software" bundles
  • unrelated installers
  • binaries hosted outside official project channels

Always verify:

  • release source
  • archive names
  • SHA256 checksums
  • repository ownership

before executing downloaded binaries.


Reporting a Vulnerability

If you discover a security vulnerability, please report it privately.

You can:

  • open a GitHub Security Advisory
  • or contact the maintainers directly through GitHub

Please include when possible:

  • affected version
  • operating system
  • reproduction steps
  • impact description
  • proof-of-concept

Please avoid publicly disclosing vulnerabilities before a fix is available.


Security Expectations

Standardoc is currently under active beta development.

During beta development:

  • APIs may evolve
  • internal protocols may change
  • extension/runtime compatibility may require matching versions

Users are encouraged to keep both the extension and runtime binaries up to date.

Always use official distributions and verify binary integrity before execution.

There aren't any published security advisories