Skip to content

Security: nowo-tech/ControllerKitBundle

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x
< 1.0

Reporting a Vulnerability

We take the security of ControllerKitBundle seriously. If you believe you have found a security vulnerability, please report it privately:

Please include:

  • Type of issue (e.g., injection, XSS, auth bypass, deserialization risk, etc.)
  • Affected file(s) and version/tag/commit
  • Steps to reproduce
  • Impact assessment
  • PoC (if available)

Response Timeline

  • Initial acknowledgment: within 48 hours
  • Follow-up status: within 7 days
  • Resolution: depends on complexity and impact

Disclosure Policy

  • We confirm receipt and validate the report.
  • We prepare and publish a fix as soon as possible.
  • We coordinate disclosure with the reporter.
  • We credit responsible disclosure (unless anonymity is requested).

For technical details and the release security checklist, see docs/SECURITY.md.

There aren’t any published security advisories