Do not report vulnerabilities, exposed secrets, or exploitable security details in a public issue, discussion, pull request, or commit.
Use GitHub private vulnerability reporting when available. If that channel is unavailable, contact Code Huddle through https://www.code-huddle.com/contact and request a private security channel without including exploit details in the first message.
Include, when safe and relevant:
- the affected file, workflow, or example;
- impact and realistic attack conditions;
- reproduction steps or a minimal proof of concept;
- suggested mitigation; and
- whether information has been shared elsewhere.
This repository primarily contains documentation. In scope are vulnerabilities in repository automation, scripts, examples, links that create a material security risk, or accidental disclosure of secrets or sensitive information.
General disagreements with guidance, speculative weaknesses without a plausible impact, and vulnerabilities in third-party services should be reported to the appropriate owner.
Code Huddle will make a reasonable effort to acknowledge reports, assess impact, coordinate remediation, and credit responsible reporters when appropriate. This policy does not promise a particular response time, remediation, reward, or disclosure schedule.
Security cannot be guaranteed. See DISCLAIMER.md.