Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Security: iamfarhad/validation

Security

SECURITY.md

Security Policy

πŸ”’ Reporting Security Vulnerabilities

We take security seriously. If you discover a security vulnerability in Laravel Persian Validation, please report it responsibly.

πŸ“§ How to Report

DO NOT open a public GitHub issue for security vulnerabilities.

Instead, please send an email to:

  • Email: farhad.pd@gmail.com
  • Subject: [SECURITY] Laravel Persian Validation - [Brief Description]

πŸ“‹ What to Include

Please include the following information in your report:

  1. Description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact of the vulnerability
  4. Suggested fix (if you have one)
  5. Your contact information for follow-up

πŸ• Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Status Update: Every week until resolved
  • Resolution: Depends on severity and complexity

πŸ† Recognition

Security researchers who responsibly report vulnerabilities will be:

  • Credited in the security advisory (unless they prefer to remain anonymous)
  • Mentioned in our Hall of Fame (if applicable)
  • Thanked publicly after the issue is resolved

πŸ›‘οΈ Security Best Practices

For Users

  1. Keep Updated: Always use the latest version of the package
  2. Review Dependencies: Regularly audit your composer dependencies
  3. Input Validation: Use this package for validation, but also implement proper input sanitization
  4. Error Handling: Don't expose sensitive validation logic in error messages

For Contributors

  1. Secure Coding: Follow OWASP secure coding guidelines
  2. Input Validation: Validate all inputs thoroughly
  3. Dependencies: Keep dependencies updated and secure
  4. Testing: Include security test cases

πŸ” Vulnerability Types

We're particularly interested in reports about:

  • Input Validation Bypass: Ways to bypass validation rules
  • Regular Expression DoS: ReDoS vulnerabilities in regex patterns
  • Information Disclosure: Leaking sensitive information through error messages
  • Dependency Vulnerabilities: Issues in third-party dependencies

πŸ“œ Supported Versions

Version Supported
3.3.x βœ… Yes
3.2.x βœ… Yes
3.1.x ⚠️ Critical fixes only
< 3.1 ❌ No

πŸ”„ Security Updates

Security updates will be released as patch versions (e.g., 3.3.1) and will be:

  • Documented in CHANGELOG.md
  • Announced in GitHub releases
  • Published to Packagist immediately

πŸ“š Security Resources

🀝 Security Partnership

If you're a security company or researcher interested in a more formal security partnership, please contact us at farhad.pd@gmail.com.


Thank you for helping keep Laravel Persian Validation secure! πŸ›‘οΈ

There aren't any published security advisories

AltStyle γ«γ‚ˆγ£γ¦ε€‰ζ›γ•γ‚ŒγŸγƒšγƒΌγ‚Έ (->γ‚ͺγƒͺγ‚ΈγƒŠγƒ«) /