Skip to content

Latest commit

 

History

History
30 lines (20 loc) · 1.19 KB

File metadata and controls

30 lines (20 loc) · 1.19 KB

Security policy

Reporting a vulnerability

Do not disclose a vulnerability, credential, customer detail, internal infrastructure fact, or unsafe publication in a public issue or discussion.

Use GitHub private vulnerability reporting for this repository:

https://github.com/lightning-it/documentation/security/advisories/new

Include the affected path or commit, impact, safe reproduction information, and suggested remediation. Do not include live credentials or protected customer data; identify the approved secure exchange channel needed for those details.

Scope

Reports may cover the site source, custom components, build/deployment chain, dependencies, response-header policy, or accidental sensitive publication. General product support belongs in the support channels described in SUPPORT.md.

Response

Maintainers will triage privately, preserve relevant evidence, remove exposed public material when necessary, rotate or revoke affected credentials through the owning secret system, assess Git history and deployment caches, and publish an appropriately sanitized advisory when disclosure is safe.

No response-time or certification claim is made in this public policy.