If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public issue
- Email: security@g-but.ch (or use GitHub's private vulnerability reporting)
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 7 days
- Resolution Target: Within 30 days (depending on severity)
Only the latest version on the main branch is actively supported with security updates.
This repository follows security best practices including:
- Dependency scanning via Dependabot
- Secret scanning enabled
- Branch protection on main branch