Skip to content

Security: SilentMalachite/Scriptoris

Security

.github/SECURITY.md

Security Policy

Supported Versions

We release patches for security vulnerabilities. Which versions are eligible for receiving such patches depends on the CVSS v3.0 Rating:

Version Supported
0.1.x

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via GitHub's security advisory feature:

  1. Go to https://github.com/SilentMalachite/Scriptoris/security/advisories
  2. Click "Report a vulnerability"
  3. Fill out the form with details about the vulnerability

Please include the following information:

  • Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit the issue

Response Timeline

  • Initial Response: We will acknowledge receipt of your vulnerability report within 48 hours.
  • Investigation: We will investigate and validate the vulnerability within 7 days.
  • Resolution: We will work to resolve confirmed vulnerabilities within 30 days.
  • Disclosure: We will coordinate the disclosure timeline with you.

Security Updates

Security updates will be released as patch versions and announced through:

  • GitHub Security Advisories
  • Release notes
  • CHANGELOG.md

Thank you for helping keep Scriptoris secure!

There aren’t any published security advisories