Skip to content

Latest commit

 

History

History
30 lines (20 loc) · 848 Bytes

File metadata and controls

30 lines (20 loc) · 848 Bytes

Security Policy

Supported Versions

Version/Branch Supported
master Yes
dev Best effort
Older branches/tags No

Reporting a Vulnerability

Please do not open public issues for security reports.

Use GitHub's private reporting flow:

  1. Open the repository Security tab.
  2. Click Report a vulnerability.
  3. Include reproduction steps, impact, and affected version/branch.

If private reporting is unavailable, contact a maintainer directly and share details privately.

Response Targets

  • Initial triage response: within 7 days.
  • Status update after validation: within 14 days.
  • Fix timeline depends on severity, exploitability, and release risk.

Scope

This policy covers the DUMB backend codebase and repository workflows. Related projects (like dmbdb) may have separate policies.