Security Policy

April 19, 2026 ยท View on GitHub

Supported Versions

VersionSupported
2.4.x:white_check_mark:
2.3.x:white_check_mark:
< 2.3:x:

Reporting a Vulnerability

If you discover a security vulnerability within Upup, please send an email to hello@devino.com. All security vulnerabilities will be promptly addressed.

Please do not publicly disclose the issue until it has been addressed by the team.

Security Update Process

  1. The vulnerability is received and assigned to a primary handler
  2. The problem is confirmed and a list of affected versions is determined
  3. Code is audited to find any similar problems
  4. Fixes are prepared for all supported releases
  5. New versions are released and the vulnerability is publicly announced