Skip to content

Security: cocofhu/approving

Security

SECURITY.md

Security policy

Report vulnerabilities privately through GitHub Private vulnerability reporting on github.com/cocofhu/approving.

Do not disclose suspected vulnerabilities in public issues, pull requests, discussions, logs, or screenshots.

Supported versions

Only the latest published release line on GitHub Releases is supported for security fixes until a longer support matrix is published.

Response targets

  • Acknowledgement: within 3 business days
  • Status updates: at least every 7 days while the report remains open
  • Coordinated disclosure: agree on a public date after a fix or mitigation is available, or after a reasonable remediation window

Safe harbor

We will not pursue legal action against researchers who:

  • make a good-faith effort to avoid privacy violations, service disruption, and data destruction;
  • do not access or modify data that is not their own beyond what is needed to demonstrate the issue;
  • report findings promptly through the private channel above and give us a reasonable chance to remediate before public disclosure.

There aren't any published security advisories