Skip to content

Security: reverberage/.github

Security

SECURITY.md

Security Policy

Supported Versions

We release security updates for the following versions:

Version Supported
Latest
< Latest

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

What to Report

  • Buffer overflows or memory safety issues
  • SQL injection or command injection vulnerabilities
  • Authentication or authorization bypasses
  • Denial of service vulnerabilities
  • Information disclosure vulnerabilities
  • Any other security-related issue

How to Report

DO NOT open a public GitHub issue for security vulnerabilities.

Instead, please report via:

  1. GitHub Security Advisories (preferred): Use the "Security" tab in the repository to report a vulnerability privately
  2. Email: Send details to the maintainers at their GitHub profile email addresses

What to Include

When reporting a vulnerability, please include:

  • Description of the vulnerability
  • Steps to reproduce or proof of concept
  • Potential impact
  • Suggested fix (if you have one)
  • Your contact information for follow-up

Response Timeline

  • Initial response: Within 48 hours
  • Status update: Within 7 days
  • Resolution target: Within 30 days (depending on severity and complexity)

Disclosure Policy

  • We will work with you to understand and validate the issue
  • We will develop and test a fix
  • We will release the fix and coordinate disclosure
  • We will credit reporters (unless they prefer to remain anonymous)

Safe Harbor

We consider security research conducted in accordance with this policy to be "authorized" conduct under the Computer Fraud and Abuse Act. We will not pursue legal action against researchers who:

  • Act in good faith
  • Avoid privacy violations and data destruction
  • Don't degrade the quality of the service
  • Report vulnerabilities promptly

Security Best Practices

When using this project:

  1. Keep dependencies up to date
  2. Use the latest stable release
  3. Follow the principle of least privilege
  4. Validate all inputs
  5. Use secure configuration settings
  6. Monitor for security advisories

Security Updates

Security updates are announced via:

  • GitHub Security Advisories
  • Release notes
  • GitHub repository notifications

Subscribe to repository notifications to receive security update announcements.

Contact

For security-related questions, please use the reporting channels above rather than public issues or discussions.

There aren't any published security advisories