S
Supanote
Sign in Sign up

GitHub Security Policy (SECURITY.md) Vulnerability Template

markdown 13 hours ago · 44 lines · 6 views

Security Policy

We take the security of our codebase, infrastructure, and user data extremely seriously. We appreciate the responsible disclosure of any security vulnerability.


🛡 Supported Versions

Security updates and patches are provided for the following release branches:

Version Supported Notes
2.x.x ✅ Yes Current active production release
1.x.x ⚠️ Critical only Critical security vulnerabilities only
< 1.0 ❌ No End of Life — upgrade required

🚨 Reporting a Vulnerability

Please do NOT report security issues via public GitHub issues, discussions, or social media.

To report a vulnerability responsibly:

  1. Email us directly: Send full details to security@example.com.
  2. PGP Encryption: If sending sensitive proof-of-concept material, encrypt using our PGP public key:
    • Key ID: 0x9F3B21E8A7D4C610
    • Fingerprint: 84A2 91D0 5C1E 7B33 4F09 2A81 9F3B 21E8 A7D4 C610

What to include in your report:

  • Type of vulnerability (e.g., SSRF, XSS, IDOR, SQLi, Remote Code Execution).
  • Step-by-step reproduction steps or curl commands.
  • Potential impact and affected endpoints.
  • Suggested fix or mitigation (optional).

⏱ Response Timelines & SLA

  • Initial Acknowledgement: Within 24 hours.
  • Triage & Severity Assessment: Within 72 hours.
  • Fix & Deployment: Within 7 business days for High/Critical issues.
  • Public Disclosure: Coordinated after fix deployment.

No replies yet

Every reply is a note. Start a discussion, ask a question, or attach a code snippet.

Share Note

Download SVG
Social Card Preview
Open on mobile
Point your phone camera to open this note directly

Report this note

Notification