Skip to content

Security: bgrewell/iso-kit

SECURITY.md

Security Policy

Supported Versions

At this time, iso-kit is in pre-release and no stable versions are available. All released versions are considered pre-release and are subject to ongoing changes, including security updates. Once a stable version is released, this section will be updated to clearly indicate which versions are supported with security updates.

Reporting a Vulnerability

We take the security of iso-kit very seriously and appreciate your help in ensuring its integrity. If you believe you have found a security vulnerability, please use GitHub's private vulnerability reporting feature for this repository.

  1. Report Privately on GitHub:

    • Navigate to the Security tab of the repository.
    • Click on the "Report a vulnerability" button to securely submit your report.
    • Provide a detailed report including:
      • A clear description of the vulnerability.
      • Steps to reproduce the issue.
      • Any relevant logs, screenshots, or evidence that can help us diagnose the problem.
      • Your contact information (if you wish to receive updates).
  2. What to Expect:
    We will acknowledge receipt of your report within 3 business days. Depending on the severity and complexity of the issue, we may request additional information. We commit to keeping you updated on our progress as we address the vulnerability.

  3. Disclosure Policy:
    Please refrain from publicly sharing details of the vulnerability until it has been fixed and a public advisory has been issued.

Thank you for your cooperation and for helping to make iso-kit more secure for everyone.

There aren't any published security advisories