Skip to content

Security: PhillDev-coder256/lync

Security

SECURITY.md

Security Policy

Supported Versions

Currently, only the latest version of Lync is supported for security updates.

Version Supported
v1.0.x
< v1.0

Reporting a Vulnerability

We take the security of Lync seriously. If you discover a security vulnerability, please do not open a public issue. Instead, follow these steps:

  1. Send an email to the maintainer (Add your email here or use GitHub Private Vulnerability Reporting).
  2. Describe the vulnerability in detail.
  3. We will acknowledge your report within 48 hours and provide a timeline for a fix.

Security of WAL Logs

Lync acts as a privileged database user. We recommend:

  • Running Lync in a private network (sidecar pattern).
  • Using TLS for WebSocket connections in production.
  • Granting the Lync database user only the minimum required REPLICATION permissions.

There aren't any published security advisories