Skip to content

Latest commit

 

History

History
42 lines (25 loc) · 1.15 KB

File metadata and controls

42 lines (25 loc) · 1.15 KB

Security Policy

Supported Versions

Version Supported
latest Yes

We only provide security fixes for the latest release.

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly. Do not open a public GitHub issue.

Email [email protected] with:

  • A description of the vulnerability

  • Steps to reproduce

  • Any relevant logs or screenshots

  • Your suggested severity (critical, high, medium, low)

We will acknowledge receipt within 48 hours and aim to provide an initial assessment within 5 business days.

Disclosure Policy

  • We follow coordinated disclosure. We ask that you give us a reasonable window (typically 90 days) to address the issue before public disclosure.

  • Once a fix is released, we will publish a security advisory on GitHub.

  • Credit will be given to reporters unless they prefer to remain anonymous.

Scope

This policy applies to the OpenZosma repository and any officially maintained packages within this monorepo. Third-party dependencies are outside our direct scope, but we will work to address transitive vulnerabilities promptly.