# Security Policy ## Supported Versions We actively support the latest version of Xget for Chrome. Security updates are provided for: | Version | Supported | | ------- | ------------------ | | 1.x.x | :white_check_mark: | ## Reporting a Vulnerability If you discover a security vulnerability in Xget for Chrome, please report it responsibly: ### How to Report 1. **Do not** create a public GitHub issue for security vulnerabilities 2. Email the maintainer directly or create a private security advisory 3. Include as much detail as possible: - Description of the vulnerability - Steps to reproduce - Potential impact - Suggested fix (if any) ### What to Expect - **Response Time**: We aim to respond within 48 hours - **Investigation**: We will investigate and assess the severity - **Fix Timeline**: Critical vulnerabilities will be patched within 7 days - **Disclosure**: We will coordinate responsible disclosure with you ### Security Considerations This extension: - Processes URLs locally in your browser - Does not collect or transmit personal data - Uses Chrome's standard extension APIs - Redirects downloads through user-configured Xget domains ### Scope Security issues we consider in scope: - Code injection vulnerabilities - Privilege escalation - Data leakage or privacy violations - Malicious URL handling - Extension permission abuse Out of scope: - Issues with third-party Xget servers - Browser-level vulnerabilities - Social engineering attacks ## Security Best Practices When using this extension: - Only configure trusted Xget domains - Keep the extension updated - Review permissions when updating - Report suspicious behavior Thank you for helping keep Xget for Chrome secure!