Skip to content

Security: dafneb/.github

SECURITY.md

Security Policy

Introduction

Security issues happen as part of the normal lifecycle of software development.

Supported Versions

Only latest major version is supported, including last 5 minor versions.

Reporting a Vulnerability

If you discover a security issue, please follow these steps to report it:

  1. Publicly Disclosed Issues:

    • If the issue is already publicly disclosed (e.g., a CVE in one of the project's dependencies), feel free to create a GitHub issue to discuss it openly.
  2. Privately Discovered Issues:

    • For vulnerabilities that have not been publicly disclosed, we encourage you to use GitHub Security Advisories to report the issue privately and securely. This ensures the vulnerability is addressed before public disclosure.
    • Navigate to the repository's Security tab and click on Report a Vulnerability to create a private advisory.
  3. Include Relevant Details:

    • Provide as much information as possible, including steps to reproduce the issue, affected versions, and any potential impact.

We highly value your contributions and will acknowledge your efforts in helping us maintain a secure project.

Automatic scanning and fixing

Our repositories are scanned by more security tools frequently and also during push or pull requests. On the second hand, it's still possible you could find any security issue.

There aren’t any published security advisories