Skip to content

Security: kunalsuri/SkillDeck

SECURITY.md

Security Policy

Supported Versions

Currently, active development and security updates are provided for the following versions:

Version Supported
0.1.x
< 0.1.0

Reporting a Vulnerability

We take the security of SkillDeck seriously. If you find a security vulnerability, please do not report it via public issues.

Please report vulnerabilities privately using GitHub Private Vulnerability Reporting: Go to the Security tab of this repository on GitHub, select Advisories, and click on Report a vulnerability to submit a draft advisory.

What to include in your report:

  • A description of the vulnerability and its potential impact.
  • Detailed steps to reproduce the issue (including proof of concept scripts, inputs, or screenshots if applicable).
  • Details about your environment (OS version, Python version, Node.js version).

Vulnerability Handling Process

Once a vulnerability report is received, the maintainers will:

  1. Acknowledge receipt of the report within 48 hours.
  2. Investigate the issue and confirm the vulnerability.
  3. Work on a fix in a private branch/repository.
  4. Coordinate a release date for the patch.
  5. Publish a security advisory and credit the reporter (if desired).

We aim to resolve all critical security issues within 90 days of initial reporting.

There aren't any published security advisories