Skip to content

Latest commit

 

History

History
45 lines (29 loc) · 1.78 KB

File metadata and controls

45 lines (29 loc) · 1.78 KB

Security Policy

Supported Versions

This repository follows Semantic Versioning. Security fixes are applied to the latest release.

While the repo is pre-1.0, only the latest 0.x release receives security updates.

Version Supported
0.x (latest)
< 0.x (older minors)

Reporting a Vulnerability

Please do not file a public GitHub issue for security problems.

Use one of the following private channels:

  1. GitHub Private Vulnerability Reporting (preferred): open a private advisory at https://github.com/TitusKirch/skills/security/advisories/new.
  2. Email: titus.kirch@kirch.dev. PGP available on request.

Please include:

  • A description of the vulnerability and its impact.
  • Steps / prompts to reproduce.
  • The affected skill and version.
  • Any suggested fix, if you have one.

What to expect

Stage Target timeline
Acknowledgement of report within 3 business days
Initial assessment & triage within 7 business days
Patch released (if accepted) depends on severity — critical issues prioritised
Public disclosure & advisory coordinated with reporter after the patch ships

Credit

Reporters who follow this process responsibly are credited in the CHANGELOG and the corresponding GitHub Security Advisory, unless they prefer to remain anonymous.


Maintained by Titus Kirch / IT-Dienstleistungen Titus Kirch.