Skip to content

Security: harnexa/nexa-gauge

SECURITY.md

Security Policy

Supported Versions

Security fixes are currently applied to the latest main branch and the latest release line.

Version Supported
latest (main) yes
older versions no

Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Use one of these private channels:

  • GitHub Security Advisories: Security tab -> Report a vulnerability

When reporting, include:

  • affected version / commit
  • reproduction steps or proof-of-concept
  • impact assessment
  • suggested remediation (if available)

Response SLA

  • Initial acknowledgement: within 72 hours
  • Triage and severity assessment: within 7 days
  • Patch timeline: depends on severity and reproducibility

If your report is valid, we will coordinate disclosure and credit you unless you prefer to remain anonymous.

There aren't any published security advisories