Skip to content

Security: Design-Enginnering/is-a-software

Security

SECURITY.md

Security Policy

Reporting a vulnerability

If you find a security issue in is-a.software, do not open a public GitHub issue. Report it privately:

What to include

  • A description of the vulnerability
  • Steps to reproduce it
  • The potential impact
  • Any suggested fix (optional)

Disclosure timeline

  1. We'll acknowledge your report within 48 hours
  2. We'll work on a fix and keep you updated
  3. Once the fix is deployed, we'll disclose the issue publicly with credit to you (unless you prefer to remain anonymous)

Supported versions

Only the latest release on the main branch receives security patches. Always run the most recent version.

There aren't any published security advisories