Skip to content

Security: nowo-tech/DoctrineEncryptBundle

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
2.x
Before 2.0

Reporting a Vulnerability

We take the security of DoctrineEncryptBundle seriously. If you believe you have found a security vulnerability, please report it privately:

  • Email: hectorfranco@nowo.tech (see composer.json maintainers)
  • Do not open a public GitHub issue for security-sensitive bugs.

Please include:

  • Type of issue (e.g. injection, XSS, auth bypass, deserialization risk, cryptographic misuse)
  • Affected file(s) and version/tag/commit
  • Steps to reproduce
  • Impact assessment
  • PoC (if available)

Response Timeline

  • Initial acknowledgment: within 48 hours
  • Follow-up status: within 7 days
  • Resolution: depends on complexity and impact

Disclosure Policy

  • We confirm receipt and validate the report.
  • We prepare and publish a fix as soon as possible.
  • We coordinate disclosure with the reporter.
  • We credit responsible disclosure (unless anonymity is requested).

There aren’t any published security advisories