apex-sdk

Security Policy

Reporting a Vulnerability

The Apex SDK team takes security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings and will make every effort to acknowledge your contributions.

How to Report

DO NOT report security vulnerabilities through public GitHub issues.

Instead, please report them via email to kherld@duck.com.

You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

What to Include

Please include the following information in your report:

Preferred Languages

We prefer all communications to be in English.

Disclosure Policy

When we receive a security bug report, we will:

  1. Confirm the problem and determine the affected versions
  2. Audit code to find any similar problems
  3. Prepare fixes for all supported releases
  4. Release new security fix versions as soon as possible

Security Updates

Security updates will be released as patch versions and announced via:

Supported Versions

Version Supported
0.1.x :white_check_mark:
< 0.1.0 :x:

Security Measures

Apex SDK implements several security measures:

Code Security

Dependencies

Best Practices

Contact