This repository is maintained by a small team. We aim to handle security reports quickly and responsibly while balancing limited maintainer capacity.
As a template repository, security updates are applied to the main branch
baseline.
main: supported- historical snapshots/tags: best effort only
Please do not open public issues for suspected vulnerabilities.
Use one of these channels:
- GitHub Security Advisory (preferred)
- Private maintainer contact listed in
CODEOWNERS
Include:
- Affected file(s)/component(s)
- Reproduction steps or proof of concept
- Impact assessment (confidentiality/integrity/availability)
- Suggested fix (if available)
Response times are realistic rather than enterprise-scale:
- Initial acknowledgment: within 3 business days
- Triage decision: within 7 business days
- Fix target for high/critical issues: 14-30 days (best effort)
- Fix target for medium/low issues: scheduled in normal backlog
If maintainers are unavailable (holidays/incidents), timelines may extend. We will still acknowledge and communicate status updates.
- Receive private report
- Confirm and triage severity
- Prepare and validate fix
- Publish patch and advisory notes
- Credit reporter unless anonymity is requested
Projects created from this template should replace this file with project-specific:
- Security contacts
- Support windows
- Dependency and secret-management policy
- Incident response and disclosure requirements