Skip to content

Latest commit

 

History

History
32 lines (20 loc) · 1.1 KB

File metadata and controls

32 lines (20 loc) · 1.1 KB

SECURITY.md

Security Policy

Supported Versions

Only the latest published version of Servify-express receives security updates.
Older versions are not supported and may contain unresolved vulnerabilities.
Users are strongly encouraged to update to the newest release.

Reporting a Vulnerability

If you discover a vulnerability in Servify-express, please follow the steps below depending on severity:

Standard Vulnerabilities

Report through GitHub Security Advisories using the private reporting option on the repository.
This ensures the issue is disclosed responsibly and not publicly visible.

High-Severity or Sensitive Vulnerabilities

If the issue is critical, high-risk, or may impact many users, please email first:

Aarondoran@outlook.ie

Or submit a private report

This allows coordinated communication before opening an advisory.

Disclosure Expectations

  • You will receive an acknowledgement within 72 hours.
  • A fix or mitigation plan will usually be provided within 14 days, depending on complexity.
  • You will be notified before any public disclosure.