Skip to content

Security: balinesthesia/crkg

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.0.x
< 0.0.1

Reporting a Vulnerability

Please report security vulnerabilities privately to:

Email: security@crkg.dev (placeholder — update before first public release)

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Any known mitigations

We aim to acknowledge reports within 5 business days and provide a timeline for a fix within 10 business days.

Disclosure Policy

We follow a coordinated disclosure process:

  1. Report received and acknowledged
  2. Issue triaged and severity assessed
  3. Fix developed and tested
  4. Fix released and advisory published
  5. Reporter credited (with permission)

There aren't any published security advisories