ZeroUI takes the security and integrity of our industrial UI ecosystem very seriously. We appreciate responsible disclosure of any security vulnerabilities found within our code or dependencies.
We provide security updates and patches for the following versions:
| Version | Supported | Status |
|---|---|---|
| 1.8.x | ✅ | Active (Current Stable Release) |
| 1.7.x | ❌ | Maintenance Ended |
| < 1.7.0 | ❌ | End of Life (Upgrade Recommended) |
If you believe you have discovered a security vulnerability in ZeroUI, please DO NOT report it via a public GitHub issue. Instead, follow our responsible disclosure process:
Please send an email detailing the vulnerability to:
- Email: kazer.vj@gmail.com
- Subject:
[SECURITY] Vulnerability report in ZeroUI: <Short Summary>
Alternatively, you can use GitHub Private Vulnerability Reporting directly through the repository.
To help us triage and resolve the issue quickly, please include:
- A clear description of the potential vulnerability.
- The affected version(s) and runtime environment (.NET 8.0, .NET 4.6.2, etc.).
- Step-by-step instructions or minimal proof-of-concept (PoC) code to reproduce the issue.
- Potential impact and exploitation scenario.
- Suggested fix or mitigation, if known.
- Acknowledgement: We will acknowledge receipt of your vulnerability report within 48 hours.
- Assessment: The maintainers will investigate and determine the severity, affected components, and root cause.
- Coordination: We will work with you to test and validate a patch.
- Disclosure: A security advisory and a patched release will be published simultaneously. We kindly request that you do not disclose the issue publicly until a patched release has been made available to users.
Thank you for helping keep ZeroUI and its industrial users safe! 🔒