Skip to content

Security: IOST-ASCOL/IOST

Security

SECURITY.md


Security Policy πŸ”’

At IOST - Initiative for Open Source Technology, we are committed to ensuring the security and privacy of our community members and the codebase. If you discover a security vulnerability, we appreciate your responsible disclosure. 🚨

Reporting a Vulnerability πŸ“

If you believe you've found a security vulnerability in this repository, please follow these steps to report it to us:

  1. Do not open an issue or pull request: Do not disclose the vulnerability publicly. ⚠️
  2. Contact us directly: Please email us at iost.ascol@gmail.com with the details of the vulnerability. Include the following information:
    • A description of the issue. πŸ› οΈ
    • Steps to reproduce the issue. πŸ”
    • Affected versions and components, if applicable. πŸ“…
    • Any additional information or context. πŸ—¨οΈ

Accepted Vulnerabilities βœ…

We accept and encourage reports on the following types of vulnerabilities:

  • Cross-Site Scripting (XSS) 🧩
  • SQL Injection πŸ’»
  • Command Injection πŸ›‘
  • Remote Code Execution (RCE) 🌐
  • Authentication Issues πŸ”‘
  • Data Exposure πŸ“Š

What Happens Next? πŸ•’

  • We will acknowledge receipt of your report within 48 hours. πŸ“©
  • We will triage the vulnerability and work on a fix, providing updates as needed. πŸ”„
  • Once a fix is available, we will issue a patch and update the relevant documentation. πŸ“
  • We will credit you for finding the issue if you wish to be credited. πŸ™

Safe Disclosure πŸ›‘οΈ

Once the issue is resolved, we will coordinate with you to disclose the vulnerability safely, allowing users to update their systems before the vulnerability is publicly announced. πŸš€

Security Best Practices πŸ”

In addition to reporting security issues, we encourage all contributors to follow security best practices when contributing to this project, including:

  • Avoid storing sensitive information in the repository (e.g., API keys, passwords). πŸ”‘
  • Review code for security issues before submitting pull requests. βœ…
  • Follow secure coding standards to prevent vulnerabilities. πŸ§‘β€πŸ’»

Thank You! πŸ™Œ

We appreciate your help in keeping the project secure for everyone. Your responsible disclosure helps improve the security of the community and fosters a safe environment for developers. πŸ’‘


There aren’t any published security advisories