Skip to content

Security: Bitmia-ai/WeatherCLI-Sample

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in WeatherCLISample, please report it privately. Do not open a public GitHub issue for security problems.

Email: security@example.com

Please include:

  • A description of the vulnerability and its impact.
  • Steps to reproduce (proof-of-concept welcome).
  • The version of WeatherCLISample affected (weather-cli-sample --version or commit SHA).
  • Your environment (OS, Node.js version).

Response Timeline

  • Acknowledgement: within 48 hours of your report.
  • Initial assessment: within 7 days.
  • Fix or mitigation: depends on severity, but we aim for 30 days for high-severity issues.

We will keep you informed throughout the triage and resolution process and will credit you in the changelog (unless you prefer to remain anonymous).

Supported Versions

Version Supported
0.1.x Yes
< 0.1 No

Only the latest minor release line receives security patches. Please upgrade to the latest 0.1.x release before reporting a vulnerability.

Disclosure Policy

We follow a coordinated disclosure model:

  1. You report the vulnerability privately.
  2. We confirm and develop a fix.
  3. We release the fix and publish a security advisory.
  4. After 7 days (or sooner if you prefer), public details are disclosed.

Thank you for helping keep WeatherCLISample and its users safe.

There aren't any published security advisories