Skip to content

Security: BerryBytes/01cloud-api-gateway

Security

SECURITY.md

Security Policy

Supported Versions

At this stage, security updates are provided for the latest default branch.

Reporting a Vulnerability

Please report security issues privately and do not open public GitHub issues for sensitive findings.

Preferred private reporting channel:

If private advisories are unavailable for your account, contact the repository maintainers through the BerryBytes organization profile and request a private follow-up:

Include the following details:

  • Summary of the vulnerability
  • Affected files/components
  • Reproduction steps or proof of concept
  • Potential impact
  • Suggested remediation (if available)

Disclosure Process

  1. We acknowledge receipt within 3 business days.
  2. We validate and triage the report.
  3. We provide status updates during investigation.
  4. We prepare and release a fix.
  5. We coordinate responsible disclosure once patching is complete.

Scope Notes

  • Please avoid testing against systems you do not own or have permission to test.
  • Do not exfiltrate data, disrupt service, or degrade availability.

Thank you for helping keep this project and its users safe.

There aren’t any published security advisories