Skip to content

Security: groschi24/zonfig

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x.x
< 1.0

Reporting a Vulnerability

If you discover a security vulnerability in zonfig, please report it responsibly:

  1. Do not open a public GitHub issue
  2. Use GitHub Security Advisories with:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Resolution: Depends on severity, typically 2-4 weeks

Security Best Practices

When using zonfig:

  • Never commit secrets to version control
  • Use environment variables for sensitive configuration
  • Validate all configuration at startup
  • Keep zonfig and dependencies updated

There aren’t any published security advisories