Security Policy
SECURITY.md – private reporting, scope, safe harbor
Anleitung: Any project with users. The "do not open a public issue" line is the whole point – private channel only.
Vorschau
Security Policy
Supported versions
| Version | Supported |
|---|---|
| 1.x (latest) | Yes |
| < 1.0 | No |
Reporting a vulnerability
Please do not open a public issue for security reports.
Report vulnerabilities privately via:
- Email: [[email protected]]
- GitHub private vulnerability reporting: repository → Security → "Report a vulnerability"
What to include
- Description of the issue and potential impact
- Steps to reproduce or proof-of-concept
- Affected versions
- Suggested fix if you have one (optional)
What to expect
| Stage | Timeline |
|---|---|
| Acknowledgment | Within 72 hours |
| Initial assessment | Within 7 days |
| Fix or mitigation | Severity-dependent; critical issues prioritized |
| Disclosure | Coordinated with reporter after fix is released |
Scope
In scope: the application and its official releases.
Out of scope: issues in third-party dependencies (report upstream), social engineering, physical attacks, DoS via resource exhaustion already tracked.
Safe harbor
We will not pursue legal action against researchers who report in good faith, respect user privacy, and do not access or modify data that is not theirs.