Skip to content

Security: karkigrishmin/cq

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability in cq, please report it responsibly:

  1. Do not open a public GitHub issue for security vulnerabilities
  2. Email the maintainer directly at grishminkarki7@gmail.com
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix timeline: Depends on severity, typically 1-4 weeks

Scope

This policy applies to:

  • The cq CLI tool
  • Dependencies directly controlled by this project

For vulnerabilities in third-party dependencies (like CML), please report to the respective maintainers.

Recognition

Security researchers who responsibly disclose vulnerabilities will be acknowledged in the release notes (unless they prefer to remain anonymous).

There aren't any published security advisories