Skip to content

Latest commit

 

History

History
39 lines (27 loc) · 1.16 KB

File metadata and controls

39 lines (27 loc) · 1.16 KB

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly:

  1. Do not open a public GitHub issue
  2. Email the maintainer directly or use GitHub's private vulnerability reporting
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Resolution: Depends on severity (critical: ASAP, high: 2 weeks, medium/low: next release)

Security Best Practices

This repository provides templates that follow security best practices:

  • Dependency scanning with Dependabot
  • Code scanning with CodeQL (for public repos or GHAS-enabled private repos)
  • Container scanning with Trivy
  • SBOM generation for supply chain transparency
  • OpenSSF Scorecard for security posture assessment

Acknowledgments

We appreciate responsible disclosure and will acknowledge security researchers who report valid vulnerabilities.