Skip to content

Latest commit

 

History

History
executable file
·
29 lines (18 loc) · 1.53 KB

SECURITY.md

File metadata and controls

executable file
·
29 lines (18 loc) · 1.53 KB

Security Policy

Our security policy is to avoid leaving the ecosystem worse than we found it. Meaning we are not planning to introduce vulnerabilities into the ecosystem.

Our team take all security bugs seriously.

If you believe you have found a security vulnerability in this repository, please report it to us as described below.

Reporting Security Issue

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them by emailing the lead maintainer at [email protected] and include the word "SECURITY" in the subject line..

You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:

  • Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit the issue

This information will help us triage your report more quickly.

We do not offer any rewards (commonly known as "bug bounties") for reporting security issues.