Skip to content

Security: a1383n/laravel-auth-pro

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

At Laravel Auth Pro, we take security seriously. We appreciate your help in identifying and addressing security vulnerabilities responsibly. If you have discovered a security issue in this package, please follow these steps to report it:

  1. Create a GitHub Security Advisory: Go to GitHub Security Advisories to create a new security advisory. Please avoid disclosing any security-related information publicly until the issue has been addressed.

  2. Provide Details: In your security advisory, include a clear description of the vulnerability and any relevant information that can help us reproduce or understand the issue. If possible, include steps to reproduce the vulnerability.

  3. Expect a Response: Once you've created the security advisory, we will review it and work with you to assess the issue's severity and discuss potential fixes.

  4. Prepare for Disclosure: Once the vulnerability has been resolved, we will prepare a security advisory on GitHub. We'll coordinate with you to ensure you have the opportunity to update your own systems before we make the issue public.

Supported Versions

This package is actively maintained and receives security updates for the latest major version. We strongly recommend keeping your package updated to the latest version to benefit from security fixes and improvements.

Version Supported
Latest Release
Older Versions

Security Best Practices

We encourage users to follow these best practices to enhance the security of their applications:

  1. Regularly Update Dependencies: Keep your Laravel application and all its dependencies up to date, including this package.

  2. Implement Access Controls: Restrict access to sensitive parts of your application using Laravel's built-in access control features.

  3. Secure Environment Variables: Store sensitive configuration data, such as API keys and credentials, securely in your environment variables.

  4. Monitor Application Logs: Regularly review your application logs for any suspicious activity.

  5. Educate Your Team: Ensure your development team is aware of security best practices and is trained to identify and address security issues.

License

This Security Policy is subject to the terms of the LICENSE associated with this package.

Thank you for helping to keep Laravel Auth Pro secure!

There aren’t any published security advisories