Security Vulnerability Disclosure Policy

This policy covers software products and first-party plugins published on gPhotoShow.com and maintained by Gianpaolo Bottin. It also covers vulnerabilities in third-party components when they affect those products.

Manufacturer: Gianpaolo Bottin

We welcome reports of security vulnerabilities. We will assess their impact on our software and coordinate with the maintainers of affected third-party components when appropriate.

How to report

Email This email address is being protected from spambots. You need JavaScript enabled to view it. and use Security vulnerability report as the subject. This address is the single point of contact for security reports concerning all products covered by this policy.

Please include, if available:

  • The product name, version, operating system, and any affected plugin.
  • A description of the issue and its possible security impact.
  • Steps to reproduce it or a minimal proof of concept.
  • Whether you believe the issue is being exploited.
  • A way to contact you for follow-up, if you want a response.

Please do not send passwords, private keys, personal data, or other sensitive material unless we have agreed on a suitable way to receive it. If you prefer to remain anonymous, you may ask a competent CSIRT to coordinate the report.

What happens next

We will review the report, investigate the affected products and versions, and contact you if more information is needed. For a confirmed vulnerability, we will work on a fix or mitigation, test it, and explain how users can obtain the security update through the relevant product's official channel. We will coordinate public disclosure with the reporter when possible and publish information about fixed vulnerabilities so users can identify affected versions and take action.

The time needed to resolve an issue depends on its impact and complexity. We may delay detailed public disclosure when necessary to give users a reasonable opportunity to install a fix. We will handle any legally required notifications to the competent authorities.

Security support and updates

The current major release line of each product receives security support while it remains in active development. We publish a calendar support end date for each product line and review it annually, extending it when necessary so that at least five years of support remain. When a successor major release line is published, the preceding line remains supported for at least five more years. Maintenance releases, including security and bug fixes, normally share their line's support period. A release that substantially changes the product is assessed separately, regardless of its version number. The applicable end date and update instructions are provided with each product. Please install security updates when they become available.

Responsible research

Please avoid accessing or changing other people's data, disrupting services, or testing systems you do not own or have permission to test. If you unexpectedly encounter sensitive data, stop testing and tell us without including that data in your report. We ask you to coordinate disclosure of technical details that could be used to exploit an unfixed vulnerability.

This policy does not establish a bug bounty or promise payment for reports.