Skip to content

Security: de-otio/saas-foundation

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security vulnerabilities privately rather than opening a public issue.

Use GitHub's private vulnerability reporting: go to the Security tab and open a draft advisory. This keeps the report confidential until a fix is released.

If you cannot use that mechanism, email security@de-otio.org.

Please include enough detail to reproduce the issue (affected package and version, a minimal proof of concept, and the impact you have in mind).

This project is published mainly for inspection and is maintained on a best-effort basis under time constraints, so security reports are handled as time permits — acknowledgement may take a while. Reports are still welcome and read; please just don't expect a same-week turnaround.

Supported versions

These packages are pre-1.0 and released together from this monorepo. Only the latest published version of each package receives security fixes:

  • @de-otio/saas-foundation
  • @de-otio/saas-foundation-cdk
  • @de-otio/vestibulum
  • @de-otio/vestibulum-cdk

Disclosure

We follow coordinated disclosure: we will work with you on a fix and a release before any public details are published, and will credit reporters who wish to be acknowledged.

There aren't any published security advisories