Skip to content

Security: acabelloj/gh-inspector

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x

Reporting a Vulnerability

If you discover a security vulnerability within gh-inspector, please send an email to the maintainers. All security vulnerabilities will be promptly addressed.

Please do not report security vulnerabilities through public GitHub issues.

What to Include

When reporting a vulnerability, please include:

  1. A description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact of the vulnerability
  4. Any potential solutions (if known)

Response Timeline

  • We will acknowledge receipt of your vulnerability report within 48 hours
  • We will provide a detailed response within 7 days, including steps we plan to take
  • We will work to resolve critical vulnerabilities as quickly as possible

Security Best Practices

When using gh-inspector:

  1. GitHub Authentication: This tool uses GitHub CLI (gh) for authentication. Ensure your gh credentials are secured.
  2. Dependencies: Keep the tool and its dependencies up to date.
  3. Rate Limiting: Be aware of GitHub API rate limits when querying large organizations.

Disclosure Policy

  • We follow responsible disclosure practices
  • Security issues will be publicly disclosed after a fix is available
  • Credit will be given to security researchers who report issues responsibly

Thank you for helping keep gh-inspector and its users safe!

There aren't any published security advisories