Nora treats financial data with the highest level of sensitivity. Security updates and patches are provided for the current stable release and the immediate previous LTS (Long Term Support) version.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| 0.9.x | ✅ |
| 0.8.x | ❌ |
| < 0.8 | ❌ |
If you discover a security vulnerability within the Nora ecosystem, we ask that you do not report it publicly via GitHub Issues. Please follow our responsible disclosure process:
- Where to report: Send a detailed email to
info.20player11@seznam.cz. For enhanced security, we recommend encrypting your message using our PGP key (available in the contact section). - What to include: Provide a clear description of the vulnerability, steps to reproduce (PoC), and the potential impact on user data or system integrity.
- Expectations: Our security team will acknowledge receipt of your report within 24 hours.
- Process: We will provide status updates every 48 hours until the vulnerability is resolved. Once a fix is deployed, we will coordinate a public disclosure date with you.
- Bounties: We operate a Bug Bounty program for legitimate reports of critical vulnerabilities (e.g., data leaks, authentication bypass).
By following this policy, we commit to not taking any legal action against the reporter, provided that no real user data was exploited or compromised during the discovery.