| Version | Supported |
|---|---|
| 1.x.x | ✅ |
We take security seriously. If you discover a security vulnerability in this project, please report it responsibly.
- Do not open a public GitHub issue for security vulnerabilities
- Email the maintainer directly at: security@haitmg.pl
- Include as much information as possible:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours of your report
- Assessment: We will investigate and assess the severity within 7 days
- Resolution: Critical vulnerabilities will be addressed as soon as possible
- Disclosure: We will coordinate with you on public disclosure timing
This security policy applies to:
- All Terraform modules in this repository
- CI/CD configurations
- Documentation that could lead to misconfiguration
- Vulnerabilities in Terraform itself (report to HashiCorp)
- Vulnerabilities in AWS services (report to AWS)
- Issues in third-party dependencies (report to respective maintainers)
When using these modules, we recommend:
- Pin versions - Always use specific version tags, not
mainbranch - Review changes - Check release notes before upgrading
- Least privilege - Use minimal IAM permissions required
- Enable logging - Use VPC Flow Logs and CloudTrail
- Encrypt data - Enable encryption for all supported resources
We appreciate security researchers who help keep this project safe. Contributors who report valid vulnerabilities will be acknowledged in our release notes (unless they prefer to remain anonymous).
Thank you for helping keep HAIT Terraform Modules secure!