Skip to content

Latest commit

 

History

History
35 lines (23 loc) · 974 Bytes

File metadata and controls

35 lines (23 loc) · 974 Bytes

Security Policy

Supported Versions

Package Supported
qontos >= 0.1.0 Yes
qontos-sim >= 0.1.0 Yes
qontos-bench >= 0.1.0 Yes

Reporting a Vulnerability

If you discover a security vulnerability in any QONTOS package, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, send an email to: [email protected]

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected package and version
  • Potential impact assessment

We will acknowledge receipt within 48 hours and provide an initial assessment within 7 business days.

Disclosure Policy

  • We follow a 90-day coordinated disclosure timeline.
  • Security fixes are released as patch versions with advisory notices.
  • Contributors who report valid vulnerabilities will be credited (with permission) in the advisory.

Scope

This policy covers all repositories under the qontos GitHub organization.