Supported Versions
RusDox is currently maintained as a fast-moving project.
The dated v1 security review documents the threat model, enforced ZIP/XML/image/template limits, hosted boundary, supply-chain controls, and residual non-claims.
Security fixes are most likely to land in:
- the latest release line
- the current
mainbranch
Older versions may not receive fixes.
Reporting A Vulnerability
Please do not publish sensitive vulnerability details in a public issue.
Preferred path:
- Use GitHub private vulnerability reporting.
- Do not open a public issue containing exploit details, private document content, or sensitive fixtures.
When reporting, include:
- affected version or commit
- impact summary
- reproduction steps
- whether the issue affects DOCX parsing, DOCX writing, YAML parsing, PDF rendering, or the CLI
- any proof-of-concept details that help confirm the issue
What To Expect
- an acknowledgement as soon as practical
- clarification questions if needed
- a fix or mitigation plan when the report is confirmed
Scope
Examples of relevant security issues:
- unsafe parsing behavior with untrusted input
- archive handling bugs that could overwrite files unexpectedly
- vulnerabilities caused by generated output or package preservation behavior
Non-security bugs should go through the normal issue tracker.