Skip to content

Security: dyka3773/db-drift

Security

.github/SECURITY.md

Security Policy

This project is still under active development, in a very early stage, the releases are not stable yet, and we are not ready to support security issues at this time. However, we take security seriously and will update this policy as the project matures.

Reporting a Vulnerability

If you discover a security vulnerability in db-drift, please report it to us responsibly.

How to Report

  1. Do not create a public GitHub issue for security vulnerabilities
  2. Email us directly at: dyka3773@gmail.com
  3. Include the following information:
    • Description of the vulnerability
    • Steps to reproduce
    • Affected versions
    • Potential impact
    • Suggested fix (if available)

Response Timeline

  • Acknowledgment: We will acknowledge receipt of your report as soon as possible (usually within 48 hours)
  • Assessment: We will assess the vulnerability within 7 days
  • Fix: We will work on a fix and release it as soon as possible
  • Credit: We will credit you in the security advisory (unless you prefer to remain anonymous)

Security Best Practices

When using db-drift:

  1. Keep updated: Always use the latest version
  2. Validate inputs: Be cautious with dependency files from untrusted sources
  3. File permissions: Ensure proper file permissions on generated outputs
  4. CI/CD: Use in secure CI/CD environments

Scope

This security policy applies to:

  • The db-drift Python package
  • Official GitHub repository
  • Documentation and examples

Thank you for helping keep db-drift secure!

There aren't any published security advisories