Skip to content

Security: webuild-consortium/webuild-attestation-rulebooks-catalog

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you discover a security vulnerability in this project, please report it through GitHub Security Advisories. This ensures your report is handled privately and responsibly.

Do not open a public issue for security vulnerabilities.

What to include

When reporting a vulnerability, please provide:

  • A clear description of the issue.
  • Steps to reproduce the vulnerability, if applicable.
  • The affected files, schemas, or components.
  • The potential impact (e.g. data exposure, schema bypass, trust model weakness).

What counts as a security issue

In the context of this project, security issues may include:

  • Schema design flaws that could allow invalid or malicious data to pass validation.
  • Issues that could undermine the trust model or integrity of credential data.
  • Exposure of sensitive information through sample data or documentation.

Response process

  • We aim to acknowledge reports within 5 working days.
  • We will work with you to understand and validate the issue.
  • Fixes will be applied to the main branch. There is no backporting to previous versions.

Supported versions

Only the latest version on the main branch is actively maintained.

There aren't any published security advisories