Skip to content

Security: LabRedesCefetRJ/WeGIA

SECURITY.md

Security Policy

🔐 How to Contribute to WeGIA's Security

You can help improve the security of the WeGIA project by analyzing the code during the design phase, running a local instance on your computer, or using the public test server.

🚨Please do not submit vulnerabilities through other means like VulnDB plataform. Our vulnerability disclosure policy is fully centered on GitHub Advisory.🚨


🧠 Design-Time Analysis

To test WeGIA’s code during the design phase, clone the repository and use static analysis tools. Here are some suggestions:


🖥️ Runtime Testing (Local Instance)

You can use a virtual machine with WeGIA pre-installed to run your security tests.


🌐 Runtime Testing (Public Server)

You can use a public server with WeGIA pre-installed to run your security tests.


📦 Supported Versions

The following table indicates which versions of WeGIA receive security updates:

Version Supported
≥ 3.6 ✅ Yes
< 3.6 ❌ No

Only versions 3.4 and above are actively maintained for security.


🛡️ Reporting a Vulnerability

If you discover a security vulnerability in WeGIA, we encourage responsible disclosure.

Please include the following details if possible:

  • Description of the issue
  • Steps to reproduce
  • Affected version(s)
  • Potential impact

We aim to respond within 72 business hours.


Thank you for helping to keep WeGIA secure.

Learn more about advisories related to LabRedesCefetRJ/WeGIA in the GitHub Advisory Database