Author: Julien (Éole) Avarre (hi@eole.me)
We take the security of Jobby seriously. If you believe you have found a security vulnerability, please report it to us privately so we can resolve it before public disclosure.
| Version | Supported |
|---|---|
| 1.x | ✅ |
| < 1.0 | ❌ |
Please do not open a public issue for security vulnerabilities. Instead, report them privately using one of the following methods:
- Email: Send a detailed report to hi+jobby@eole.me (Julien Avarre).
- GitHub Security Advisory: Submit a private advisory request directly on the GitHub repository at
https://github.com/gnueole/jobby-md2html/security/advisories/new.
- A description of the vulnerability and its potential impact.
- Detailed steps to reproduce the issue (including any proofs of concept, sample requests, or payload scripts).
- Any recommended fixes or mitigations if you have them.
- Acknowledgment: We will acknowledge receipt of your report within 48 hours.
- Triage: We will investigate the issue and coordinate with you on confirmation and timeline.
- Resolution: If confirmed, we will develop a patch and release an update. We ask that you give us reasonable time to fix the issue before public disclosure.
- README - Project overview, architecture, directives and guide.
- Installation Guide - Learn how to set up Jobby locally or via Docker.
- Changelog - Review releases and change history.
- License - View the MIT License terms.