Skip to content

Latest commit

 

History

History
47 lines (30 loc) · 1.62 KB

File metadata and controls

47 lines (30 loc) · 1.62 KB

Security Policy

Supported Versions

Version Supported
Latest main branch Yes
Latest tagged release (v0.1.x) Yes
Older releases No

Security fixes are developed on main first and then included in the next published release.

Report a Vulnerability

Please report suspected vulnerabilities privately through GitHub's private vulnerability reporting flow for this repository:

Do not open a public issue for security-sensitive reports.

When possible, include:

  • A clear description of the issue and affected area
  • Reproduction steps or a proof of concept
  • Expected impact
  • Suggested mitigation, if known

Response Timeline

  • Initial acknowledgment: within 5 business days
  • Triage and severity assessment: within 10 business days when the report is reproducible
  • Status updates: provided during investigation when there is meaningful progress

If the issue is confirmed, a fix will be prepared and released as soon as practical based on severity and exploitability.

Disclosure Policy

Please allow time for investigation and remediation before public disclosure.

The preferred process is coordinated disclosure:

  1. Report privately through GitHub Security Advisories.
  2. Work with the maintainer on validation and remediation details.
  3. Publish a public advisory after a fix or mitigation is available.

If a report is out of scope or cannot be reproduced, the maintainer will close it with rationale.