Do not report a suspected security vulnerability in a public issue.
Use GitHub's private vulnerability reporting feature for the affected repository when it is available. If the repository does not provide private vulnerability reporting, email security@decort.tech.
Include the following information when possible:
- The affected project and version.
- A description of the vulnerability and its potential impact.
- Steps or code that reproduce the issue.
- Relevant configuration or environment details.
- A suggested remediation, if you have one.
Remove credentials, personal data, and unrelated sensitive information from the report.
Project maintainers review reports but do not guarantee a response or remediation time.
Coordinate public disclosure with the project maintainers so that they have an opportunity to investigate the report, prepare a fix, and notify affected users.
A project-specific security policy defines supported versions when applicable. If a project does not publish a policy, maintainers assess reports against the latest release and the current default branch. This assessment does not guarantee a fix or continued support for a version.
deCort.tech projects are provided under their respective open-source licenses. This policy does not create a commercial support agreement or guarantee that a reported issue will be remediated.