Skip to content

Security: slxca/dockerlens

SECURITY.md

Security Policy

Supported Versions

Security updates are provided only for the latest released version.

Version Supported
latest
older

Reporting a Vulnerability

Do not open public GitHub issues for security vulnerabilities.

Report security issues responsibly using one of the following methods:

Include as much detail as possible:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Affected versions
  • Proof of concept (if available)

Disclosure Process

  1. Report received and acknowledged within 72 hours.
  2. Vulnerability triaged and validated.
  3. Fix developed and tested.
  4. Coordinated disclosure via GitHub Security Advisory.
  5. Patch released.

Scope

In scope:

  • Source code in this repository
  • Official releases and containers
  • Configuration defaults

Out of scope:

  • Third-party dependencies (report upstream)
  • Misconfiguration by end users
  • Denial of service via resource exhaustion

Security Updates

Security fixes are released as soon as reasonably possible. No backporting to unsupported versions.

Credit

Responsible disclosure will be credited unless anonymity is requested.

There aren’t any published security advisories