Skip to content

Security: matcastaneda/rut-toolkit

Security

SECURITY.md

Security Policy

Supported Versions

We are currently in active development. We provide security support for the latest minor versions.

Version Supported
0.1.x
< 0.1

Reporting a Vulnerability

If you believe you have found a security vulnerability in @rut-toolkit (such as ReDoS in our parsing algorithms, prototype pollution, etc.), please responsibly disclose it. Do not open a public issue.

Option 1: GitHub Private Reporting (Preferred)

You can report the vulnerability directly through GitHub's native Private Vulnerability Reporting:

  1. Go to the Security tab of this repository.
  2. Click on Advisories in the left sidebar.
  3. Click the Report a vulnerability button.
  4. Fill out the form with the necessary details, reproduction steps, and potential impact.

Option 2: Email

Alternatively, you can report it by sending an email directly to matcastaneda.oss@gmail.com. This ensures that the information remains confidential and secure until we can address the issue.

Our Commitment

  • Acknowledge: We will acknowledge receipt of your report within 48 hours.
  • Fix: We will prioritize a fix for any critical vulnerabilities and provide a patch release as soon as possible.
  • Credit: We will publicly provide credit to the reporter in our GitHub security advisories and release notes (unless you prefer to remain anonymous).

There aren’t any published security advisories