Skip to content

Security: koshihq/koshi-runtime

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.2.x (current) Yes — design-partner support
< 0.2.0 No

Reporting a Vulnerability

If you discover a security vulnerability in Koshi Runtime, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

If this repository has GitHub private vulnerability reporting enabled, use the "Report a vulnerability" button on the Security tab to submit your report privately. Include:

  • A description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Any potential impact assessment

If private vulnerability reporting is not yet enabled for this repository, please hold your report until a private channel is available. Maintainers: enable GitHub private vulnerability reporting and update this file with the active reporting path before advertising a disclosure channel.

Disclosure Policy

We follow coordinated disclosure. We ask that you give us reasonable time to address the issue before public disclosure.

We will credit reporters in the release notes unless you prefer to remain anonymous.

There aren’t any published security advisories