Skip to content

Security: NotY215/AutoTotem

Security

SECURITY.md

Security Policy

Supported scope

Security reports should cover the current code and supported release paths of AutoTotem.

Reporting a vulnerability

Please report suspected security vulnerabilities privately through the GitHub security reporting features available for this repository. If private reporting is unavailable, contact the maintainer through the repository's GitHub profile before publishing technical details.

Do not open a public issue containing an unpatched vulnerability, credentials, tokens, private user data or exploit instructions.

Include, when safe:

  • affected version or commit
  • affected component or file
  • reproduction steps
  • expected and actual behavior
  • impact assessment
  • a minimal proof of concept when necessary

Response

Reports will be reviewed as soon as practical. The maintainer may request additional information, prepare a fix, and publish a security advisory when appropriate.

Third-party dependencies and bundled components may have separate security policies. Their security issues should also be reported to their respective maintainers when appropriate.

There aren't any published security advisories