Skip to content

Security: I-am-PUID-0/DUMB

SECURITY.md

Security Policy

Supported Versions

Version/Branch Supported
master Yes
dev Best effort
Older branches/tags No

Reporting a Vulnerability

Please do not open public issues for security reports.

Use GitHub's private reporting flow:

  1. Open the repository Security tab.
  2. Click Report a vulnerability.
  3. Include reproduction steps, impact, and affected version/branch.

If private reporting is unavailable, contact a maintainer directly and share details privately.

Response Targets

  • Initial triage response: within 7 days.
  • Status update after validation: within 14 days.
  • Fix timeline depends on severity, exploitability, and release risk.

Scope

This policy covers the DUMB backend codebase and repository workflows. Related projects (like dmbdb) may have separate policies.

There aren’t any published security advisories