Skip to content

Security: svyatov/sec_id

SECURITY.md

Security policy

Supported versions

Version Supported
7.x Yes
< 7.0 No

Fixes land on the current major only.

Reporting a vulnerability

If you discover a security vulnerability in SecID, please report it through GitHub Security Advisories.

Do not open a public issue for security vulnerabilities.

What to expect

  • Acknowledgment within 48 hours of your report
  • Initial assessment within 1 week
  • Fix and disclosure coordinated with you before public release

Disclosure policy

We follow coordinated disclosure. Once a fix is released, we will:

  1. Publish a GitHub Security Advisory
  2. Release a patched gem version
  3. Credit the reporter (unless anonymity is requested)

There aren't any published security advisories