Skip to content

Security: Qezta/infra

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest
Older

Security patches are released for the latest version. Older versions may receive fixes at the maintainers' discretion.

Reporting a Vulnerability

Please do not open a public issue for suspected security vulnerabilities.

Report privately through GitHub Security Advisories for this repository. If private reporting isn't available in your environment, contact the maintainers through the contact link on their GitHub profile.

A useful report includes:

  1. A clear description of the vulnerability and its impact
  2. Steps to reproduce, or a proof-of-concept
  3. Affected versions or commits
  4. Any known mitigations or workarounds

Response Timeline

  • Acknowledgement: within 3 business days
  • Triage & severity assessment: within 7 business days
  • Patch for critical issues: target within 30 days

Disclosure Policy

We follow coordinated disclosure: we will work with you on a fix and agree on a disclosure date before any public announcement. Please give us a reasonable window before publishing details.


Optional: tailor the supported-versions table, response timeline, and reporting channel to your project's release cadence and community norms.

There aren't any published security advisories