Skip to content

Latest commit

 

History

History
39 lines (26 loc) · 1.19 KB

File metadata and controls

39 lines (26 loc) · 1.19 KB

Security Policy

Supported Versions

Version Supported
2.x
< 2.0

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Please report vulnerabilities through GitHub Security Advisories. This ensures the report remains private while we work on a fix.

Include the following in your report:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours of receipt
  • Initial assessment: Within 1 week
  • Fix development: Depends on severity; critical issues are prioritized

Disclosure Policy

We follow coordinated disclosure:

  1. Reporter submits vulnerability via GitHub Security Advisories.
  2. We acknowledge and begin investigation.
  3. We develop and test a fix.
  4. We release the fix and publish a security advisory.
  5. Public disclosure occurs after the fix is released, with a maximum 90-day window from initial report.

We credit reporters in the advisory unless they prefer to remain anonymous.