If you discover a security vulnerability, please report it responsibly.
- Email: security@example.com (replace with actual contact)
- GitHub Issues: Private vulnerability reports
- Critical: 24 hours
- High: 3 days
- Medium: 7 days
- Low: 14 days
- Description of the issue
- Steps to reproduce
- Impact assessment
- Suggested remediation (if any)
Only the latest version of the project receives security updates.
Security vulnerabilities in:
- Application code
- Dependencies
- Build process
- Deployment configuration
Out of scope:
- User's local environment
- Third-party services (unless directly caused by our code)
- Features marked as experimental
- Keep dependencies updated
- Use HTTPS in production
- Validate all user inputs
- Follow secure coding practices
Thank you for helping keep this project secure!