Skip to content

Security: Rauch-Tech/cli

SECURITY.md

Security Policy

Reporting a Vulnerability

Rauch Tech takes the security of our software products and services seriously. If you believe you have found a security vulnerability in this repository, we encourage you to let us know right away.

How to Report

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, please report security issues privately to:

Email: security@rauchtech.example

What to Include

When reporting a security issue, please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any suggestions for remediation (optional)
  • Your contact information for follow-up

Response Process

  1. Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours.

  2. Assessment: Our security team will investigate and assess the reported vulnerability.

  3. Communication: We will keep you informed of our progress throughout the investigation.

  4. Resolution: Once a fix is developed, we will coordinate the disclosure timeline with you.

Response Expectations

  • Initial Response: Within 48 hours
  • Status Updates: At least every 5 business days
  • Resolution Timeline: Varies based on severity and complexity

Coordinated Disclosure

We practice coordinated disclosure and will work with you to:

  • Understand the full scope of the vulnerability
  • Develop and test a fix
  • Determine an appropriate disclosure timeline
  • Credit you for the discovery (if desired)

Security Updates

Security updates will be released as soon as possible after a vulnerability is confirmed and a fix is available. Updates will be announced through:

  • GitHub Security Advisories
  • Release notes
  • Our security mailing list (if applicable)

Scope

This security policy applies to:

  • The latest released version of this software
  • The main development branch

Out of Scope

  • Vulnerabilities in dependencies (please report to the respective maintainers)
  • Issues in unsupported or end-of-life versions

Best Practices

When using this software, we recommend:

  • Always use the latest stable version
  • Follow security best practices for your deployment environment
  • Regularly review and update dependencies
  • Monitor security advisories

PGP Key

For sensitive communications, you may use our PGP key:

  • Key ID: (To be added)
  • Fingerprint: (To be added)

Bug Bounty

At this time, Rauch Tech does not have a formal bug bounty program. However, we greatly appreciate security researchers who responsibly disclose vulnerabilities to us.

Contact

For general security questions or concerns:

For other inquiries:

Thank you for helping keep Rauch Tech and our users safe!

There aren't any published security advisories