Skip to content

Latest commit

 

History

History
37 lines (24 loc) · 1020 Bytes

File metadata and controls

37 lines (24 loc) · 1020 Bytes

Security Policy

Supported Versions

The repository is under active development and security fixes are applied to main.

Reporting a Vulnerability

Do not open public issues for vulnerabilities.

Preferred process:

  1. Open a private report via GitHub Security Advisories.
  2. If advisories are unavailable, open a minimal issue requesting a private channel without exploit details.

What to Include

  • Affected area (route, component, script, dependency)
  • Reproduction steps
  • Impact assessment
  • Suggested mitigation (if known)

Response Targets

  • Initial triage: within 7 calendar days
  • Confirmed issue and mitigation plan: as soon as practical based on severity
  • Public disclosure: after fix availability and coordinated disclosure window

Scope Notes

Security reports can include:

  • authentication/authorization bypass
  • data exposure or privilege escalation
  • injection or remote code execution vectors
  • secrets handling and key management issues
  • dependency supply-chain vulnerabilities