Skip to content

Security: adhit-r/fairmind

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
v1.0.x
< 1.0

Reporting a Vulnerability

We take the security of FairMind very seriously. If you have discovered a security vulnerability in FairMind, please report it to us as described below.

Please do not report security vulnerabilities through public GitHub issues.

How to Report

Please email us at security@fairmind.xyz with a description of the vulnerability. We encourage you to use [PGP] to encrypt your communications with us.

Please include the following details in your report:

  • The type of vulnerability (e.g., XSS, SQLi, RCE)
  • Full paths to source file(s) related to the manifestation of the vulnerability
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the vulnerability, including how an attacker might exploit it

Response

We will acknowledge receipt of your report within 24 hours. We will then work with you to understand and resolve the issue.

Disclosure Policy

We ask that you give us a reasonable amount of time to fix the vulnerability before disclosing it to the public. We will notify you when the vulnerability is fixed and when it is safe to disclose.

There aren’t any published security advisories