Skip to content

Security: thangldw/awesome-maintainer-defense

SECURITY.md

Security policy

Private reporting route and support boundary for the auditor, installer, shipped workflows, and release artifacts.

Reporting a vulnerability

Use GitHub private vulnerability reporting for vulnerabilities in the auditor, installer, starter-kit workflows, or release artifacts. Include the affected version and file, realistic impact, minimal reproduction, and a mitigation when available.

Do not open a public issue containing credentials, exploit details for an unpatched vulnerability, or personal information.

Listed projects

A catalog entry is not maintained by this project and is not a security endorsement. Report vulnerabilities in a listed resource to that resource's maintainers. You may open a normal issue here to flag a dead link, an abandoned project, a misleading description, or a resource that no longer meets the inclusion bar.

Supported versions

Only v1.0.0 and the latest commit on the default branch are maintained. Verify release checksums, pin Actions, review upstream changes, and test defenses in a non-critical repository before deployment.

There aren't any published security advisories