Skip to content

Security: luckycrm/Timey

SECURITY.md

Security Policy

Supported Versions

Security updates are provided for:

  • main branch (latest)

Reporting a Vulnerability

Please do not open public issues for security vulnerabilities.

Use one of these private channels:

  1. GitHub Security Advisories (preferred)
  2. Maintainer contact via private GitHub message

Include:

  • Affected component/file
  • Reproduction steps or proof of concept
  • Impact assessment
  • Suggested mitigation (if available)

Response Targets

  • Initial triage: within 72 hours
  • Status update: within 7 days
  • Fix timeline: depends on severity and complexity

Disclosure

We follow coordinated disclosure. Please allow time for a patch before public disclosure.

There aren’t any published security advisories