Skip to content

Security: silassdev/ideal-fortnight

SECURITY.md

SECURITY.md

Reporting a Vulnerability

If you believe you have found a security vulnerability in this project, please follow the steps below so we can triage and remediate it quickly and safely.

Contact (preferred)

  • Email: silasssdev@gmail.com

If you prefer encrypted reports, send to the same email using the project's PGP key (publish the key in this repository or provide a URL to it). If you do not have a PGP key, send the report by email and mark the message as sensitive.

What to include in your report

Please include the following information (as much as possible):

  • Affected component(s) and version(s) (example: backend v5.1.3, web client v4.0.2)
  • A clear description of the issue and impact
  • Steps to reproduce (minimal reproducible example or PoC)
  • Expected and actual behavior
  • Any exploit code or proof-of-concept (attach as patch or text)
  • HTTP request/response samples, logs, or stack traces if applicable
  • Your contact information and preferred disclosure method
  • Whether you are willing to coordinate disclosure and share timeline constraints

Response expectations

  • Acknowledgment: within 48 hours (we will confirm receipt and next steps).
  • Initial triage / status update: within 72 hours after acknowledgment.
  • Remediation plan: we will propose a remediation plan and ETA as soon as possible; target is to publish a fix or mitigation within 30 days for critical issues where feasible. If more time is required, we will provide regular status updates.
  • Coordinated disclosure: we prefer to coordinate public disclosure with reporters. By default, we follow a 90-day coordinated disclosure window for critical issues unless an agreed alternative is reached.

Handling & classification

  • We will classify reported issues according to severity (Low / Medium / High / Critical) and prioritize accordingly.
  • We reserve the right to accelerate disclosure for issues that are actively exploited or present an unacceptable risk if not publicly disclosed.

Credit & disclosure

  • Reporters who follow this policy and provide actionable reports may be credited in release notes or the repository's acknowledgments, unless they request anonymity.
  • We will not publish your personal information without explicit consent.

Legal & safe harbor

  • If you report a vulnerability in good faith and follow this policy, we will not pursue legal action against you for your findings.
  • Do not exploit the vulnerability beyond what is necessary to reproduce the issue. Do not access or exfiltrate data that is not yours.

If email is not possible

  • Submit a GitHub Security Advisory (if the repository is hosted on GitHub) or open a ticket in the vendor's private security intake channel as applicable.
  • For critical or emergency situations, include “CRITICAL VULNERABILITY” in the subject and call the published emergency contact number if one exists.

After a fix is available

  • We will publish release notes and, where appropriate, CVE assignments for fixed issues.
  • We will work with you to coordinate public disclosure if you opt-in to coordinated disclosure.

Miscellaneous

  • This policy may be updated from time to time. The latest version is the authoritative policy.
  • If you are unsure whether something is a security vulnerability, please report it — we will triage.

There aren't any published security advisories