Skip to content

Security: liebemama/RepoSmith

SECURITY.md

๐Ÿ”’ Security Policy

Supported Versions

We actively support and provide security updates for the following versions of RepoSmith:

Version Supported
Latest (main) โœ… Full support
Older โš ๏ธ Best-effort only

Reporting a Vulnerability

If you discover a security vulnerability in RepoSmith, please do not open a public issue.
Instead, report it through one of the following channels:

When reporting, please include:

  1. A clear description of the vulnerability.
  2. Steps to reproduce the issue.
  3. The potential impact (e.g., data leak, privilege escalation).
  4. Any suggested fix or mitigation (if available).

Security Response Process

  1. We will acknowledge your report within 48 hours.
  2. A maintainer will investigate and confirm the issue.
  3. If confirmed, we will work on a fix and prepare a security release.
  4. You will be notified once the fix is published.

Dependencies & Automated Scanning

To keep RepoSmith secure, we rely on GitHubโ€™s built-in security tooling:

  • ๐Ÿ›  Dependabot Alerts โ†’ Automatically notifies us about vulnerable dependencies.
  • ๐Ÿ” Code Scanning (CodeQL) โ†’ Detects potential vulnerabilities and coding errors.
  • ๐Ÿ•ต๏ธ Secret Scanning โ†’ Prevents accidental leaks of tokens, keys, or credentials.

We review alerts regularly and patch vulnerabilities as soon as possible.


Responsible Disclosure

We kindly ask you to follow responsible disclosure practices:

  • Do not publicly share details of the vulnerability until a fix has been released.
  • Avoid exploiting the vulnerability beyond what is necessary for proof of concept.

Thank you for helping us keep RepoSmith and its community safe! ๐Ÿš€

There arenโ€™t any published security advisories