Skip to content

Security: SBALAVIGNESH123/sketchlog

Security

SECURITY.md

Security Policy

Supported Versions

We provide security updates for the current major version. Users are strongly encouraged to stay on the latest available minor version.

Version Supported
1.x.x
< 1.0.0

Reporting a Vulnerability

If you discover a security vulnerability, please do NOT open a public issue.

Please report all security vulnerabilities via the GitHub Security Advisories tab in this repository. If you do not have access to this feature, please email the project owner directly.

What to Include

  • A clear description of the vulnerability.
  • The versions of Sketchlog affected.
  • A minimal reproduction or Proof of Concept (PoC).
  • Any potential impact or exploit scenarios.

Response Targets

  • Initial Acknowledgement: Within 48 hours.
  • Vulnerability Confirmation & Triage: Within 5 days.
  • Patch Development: Varies by complexity, but we aim for 14 days.

Security Remediation Targets & Release Blocking Policy

These are public maintainer targets for the open-source project, not a commercial or contractual service-level agreement. To protect users and the software supply chain, confirmed vulnerabilities block releases as follows:

  • Critical / High Severity: Must be patched within 30 days. No new feature releases or non-security patches will be published until the vulnerability is resolved.
  • Medium / Low Severity: Will be patched in the next scheduled minor release.

Coordinated Disclosure

We believe in responsible, coordinated disclosure. If you report a vulnerability, we ask that you keep the details confidential until we have published a fix and issued an official security advisory. In return, we commit to transparent communication and will credit you (with your permission) in the release notes and advisory.

Learn more about advisories related to SBALAVIGNESH123/sketchlog in the GitHub Advisory Database