Skip to content

Latest commit

 

History

History
33 lines (21 loc) · 1.04 KB

File metadata and controls

33 lines (21 loc) · 1.04 KB

Security Policy

Supported Versions

This repository is supported on the develop branch only.

Version Supported
develop Yes
Older branches and tags No

Reporting a Vulnerability

Do not open a public issue for security problems.

Use GitHub's private vulnerability reporting flow from the repository Security tab when it is available. If that option is not visible, contact the maintainer privately through the contact methods listed on Dan Knauss's profile or dan.knauss.ca.

Include:

  • Affected code path, API, or workflow
  • Reproduction steps or a proof of concept
  • Impact assessment
  • Suggested mitigation if you have one

Response Targets

  • Initial triage response: within 5 business days
  • Status update after validation: within 10 business days
  • Public disclosure: only after a fix or mitigation is available

Scope

Reports may cover plugin behavior, author attribution data handling, build and test workflows, or packaging and release automation.