Currently, only the latest version of Lync is supported for security updates.
| Version | Supported |
|---|---|
| v1.0.x | ✅ |
| < v1.0 | ❌ |
We take the security of Lync seriously. If you discover a security vulnerability, please do not open a public issue. Instead, follow these steps:
- Send an email to the maintainer (Add your email here or use GitHub Private Vulnerability Reporting).
- Describe the vulnerability in detail.
- We will acknowledge your report within 48 hours and provide a timeline for a fix.
Lync acts as a privileged database user. We recommend:
- Running Lync in a private network (sidecar pattern).
- Using TLS for WebSocket connections in production.
- Granting the Lync database user only the minimum required
REPLICATIONpermissions.