Skip to content

Security: dragos-cojocari/iss

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly by following these steps:

  1. Do not open a public issue or pull request
  2. Do not disclose the vulnerability publicly until it has been addressed
  3. Contact the project maintainers directly through private channels

What to Include in Your Report

When reporting a security vulnerability, please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any suggested fixes or mitigations (if applicable)

Response Timeline

We take security vulnerabilities seriously and will respond to reports as quickly as possible. You can expect:

  • Initial Response: Within 48-72 hours of your report
  • Status Updates: Regular updates on the progress of addressing the vulnerability
  • Resolution: We will work to address confirmed vulnerabilities in a timely manner

Supported Versions

Please refer to the project documentation for information about which versions are currently supported with security updates.

Security Best Practices

When using this project:

  • Keep dependencies up to date
  • Follow secure coding practices
  • Use the latest stable version when possible
  • Review and understand the code before deploying to production

Disclosure Policy

We follow responsible disclosure practices:

  • Security issues will be addressed privately before public disclosure
  • Credit will be given to security researchers who report vulnerabilities responsibly
  • Public disclosure will only occur after a fix has been released and users have had time to update

Thank you for helping keep this project secure.

There aren't any published security advisories