Skip to content

Latest commit

 

History

History
29 lines (18 loc) · 783 Bytes

File metadata and controls

29 lines (18 loc) · 783 Bytes

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Scrooge, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, please email: fabricio@fabricio.dev

Include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 1 week
  • Fix or mitigation: best effort, typically within 2 weeks

Scope

This policy covers the Scrooge codebase and its default configuration. Third-party dependencies are managed via Dependabot and npm audit.

Supported Versions

Only the latest release on the main branch is supported with security updates.