Skip to content

Latest commit

 

History

History
51 lines (33 loc) · 1.34 KB

File metadata and controls

51 lines (33 loc) · 1.34 KB

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities via public GitHub issues.

Option 1: GitHub Private Vulnerability Reporting (Preferred)

Use GitHub's built-in private reporting:

  1. Go to the Security tab of the affected repository
  2. Click "Report a vulnerability"
  3. Fill in the details

This keeps the report private and within GitHub, and allows coordinated disclosure.

Option 2: Email

What to include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgement: Within 48 hours
  • Assessment: Within 1 week
  • Fix timeline: Depends on severity — critical issues within 30 days where possible

Supported Versions

Version Supported
Latest release
Previous minor
Older versions

Disclosure Policy

We follow coordinated disclosure. We ask that you:

  1. Give us reasonable time to address the issue before public disclosure
  2. Make a good faith effort to avoid privacy violations, data destruction, or service disruption
  3. Do not access or modify other users' data

We will credit reporters who follow responsible disclosure practices.