We take security seriously and actively maintain security updates for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
| < 1.0 | ❌ |
If you discover a security vulnerability in this package, please help us by reporting it responsibly.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report security vulnerabilities by emailing:
- Email:
security@cerberus-iam.dev - Subject:
[SECURITY] Vulnerability in cerberus/laravel-iam
When reporting a security vulnerability, please include:
- Description: A clear description of the vulnerability
- Impact: Potential impact and severity
- Steps to Reproduce: Detailed reproduction steps
- Affected Versions: Which versions are affected
- Mitigations: Any known workarounds or mitigations
- Contact Information: How we can reach you for follow-up
- Acknowledgment: We will acknowledge receipt within 48 hours
- Investigation: We will investigate and validate the report
- Fix Development: We will develop and test a fix
- Disclosure: We will coordinate disclosure with you
- Release: We will release the fix and security advisory
We follow responsible disclosure practices:
- We will keep you informed throughout the process
- We will credit you (if desired) in our security advisory
- We will not disclose details until a fix is available
- We will release fixes as quickly as possible
Security updates will be:
- Released as patch versions (e.g., 1.2.3 → 1.2.4)
- Documented in the CHANGELOG.md
- Announced via GitHub Security Advisories
- Tagged with appropriate security labels
When using this package:
- Keep Dependencies Updated: Regularly update to the latest versions
- Use HTTPS: Always configure HTTPS endpoints for OAuth
- Secure Configuration: Store secrets securely (not in version control)
- Monitor Logs: Monitor for unusual authentication patterns
- Validate Inputs: Always validate and sanitize user inputs
For security-related questions or concerns:
- Email:
security@cerberus-iam.dev - Response Time: Within 48 hours for vulnerability reports