Skip to content

Security: a-organvm/system-governance-framework

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

If you believe you've found a security issue in this repository, please do not open a public issue.

How to Report

  • Preferred: Use GitHub's Private Security Advisory feature
  • Alternative: Contact the maintainers directly at security@[domain] or through the repository owner's GitHub profile

What to Include

Please provide:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Any relevant logs, screenshots, or proof-of-concept
  • Potential impact and severity assessment
  • Suggested fix (if available)

Response Timeline

  • Initial Response: Within 5 business days
  • Status Update: Within 10 business days
  • Resolution Target: Varies based on severity and complexity

Security Update Process

  1. Vulnerability is confirmed and assessed
  2. Fix is developed and tested privately
  3. Security advisory is published (if applicable)
  4. Patch is released and announced

Thank you for helping keep this project secure!

There aren’t any published security advisories