GitHub Security Policy (SECURITY.md) Vulnerability Template
markdown
13 hours ago
·
44 lines
·
6 views
Security Policy
We take the security of our codebase, infrastructure, and user data extremely seriously. We appreciate the responsible disclosure of any security vulnerability.
🛡 Supported Versions
Security updates and patches are provided for the following release branches:
| Version | Supported | Notes |
|---|---|---|
2.x.x |
✅ Yes | Current active production release |
1.x.x |
⚠️ Critical only | Critical security vulnerabilities only |
< 1.0 |
❌ No | End of Life — upgrade required |
🚨 Reporting a Vulnerability
Please do NOT report security issues via public GitHub issues, discussions, or social media.
To report a vulnerability responsibly:
- Email us directly: Send full details to
security@example.com. - PGP Encryption: If sending sensitive proof-of-concept material, encrypt using our PGP public key:
- Key ID:
0x9F3B21E8A7D4C610 - Fingerprint:
84A2 91D0 5C1E 7B33 4F09 2A81 9F3B 21E8 A7D4 C610
- Key ID:
What to include in your report:
- Type of vulnerability (e.g., SSRF, XSS, IDOR, SQLi, Remote Code Execution).
- Step-by-step reproduction steps or curl commands.
- Potential impact and affected endpoints.
- Suggested fix or mitigation (optional).
⏱ Response Timelines & SLA
- Initial Acknowledgement: Within 24 hours.
- Triage & Severity Assessment: Within 72 hours.
- Fix & Deployment: Within 7 business days for High/Critical issues.
- Public Disclosure: Coordinated after fix deployment.
1# Security Policy
3We take the security of our codebase, infrastructure, and user data extremely seriously. We appreciate the responsible disclosure of any security vulnerability.
5---
7## 🛡 Supported Versions
9Security updates and patches are provided for the following release branches:
11| Version | Supported | Notes |
12|---|---|---|
13| `2.x.x` | ✅ Yes | Current active production release |
14| `1.x.x` | ⚠️ Critical only | Critical security vulnerabilities only |
15| `< 1.0` | ❌ No | End of Life — upgrade required |
17---
19## 🚨 Reporting a Vulnerability
21**Please do NOT report security issues via public GitHub issues, discussions, or social media.**
23To report a vulnerability responsibly:
251. **Email us directly**: Send full details to `security@example.com`.
262. **PGP Encryption**: If sending sensitive proof-of-concept material, encrypt using our PGP public key:
27 - Key ID: `0x9F3B21E8A7D4C610`
28 - Fingerprint: `84A2 91D0 5C1E 7B33 4F09 2A81 9F3B 21E8 A7D4 C610`
30### What to include in your report:
31- Type of vulnerability (e.g., SSRF, XSS, IDOR, SQLi, Remote Code Execution).
32- Step-by-step reproduction steps or curl commands.
33- Potential impact and affected endpoints.
34- Suggested fix or mitigation (optional).
36---
38## ⏱ Response Timelines & SLA
40- **Initial Acknowledgement**: Within 24 hours.
41- **Triage & Severity Assessment**: Within 72 hours.
42- **Fix & Deployment**: Within 7 business days for High/Critical issues.
43- **Public Disclosure**: Coordinated after fix deployment.
Replies 0
No replies yet
Every reply is a note. Start a discussion, ask a question, or attach a code snippet.
Notification