Skip to content

Security: smykla-skalski/.github

Security

SECURITY.md

Security Policy

Supported Versions

We release patches for security vulnerabilities for the following versions:

Version Supported
latest

Reporting a Vulnerability

If you discover a security vulnerability, please report it by emailing the maintainers directly rather than opening a public issue.

Please do not report security vulnerabilities through public GitHub issues.

Contact Information

  • Email: bartek@smykla.com
  • GitHub Security Advisories: Use the "Security" tab in the relevant repository

What to Include

Please provide as much information as possible about the vulnerability:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if available)

Response Timeline

  • Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours
  • Investigation: We will investigate and validate the reported vulnerability
  • Fix: We will develop and test a fix
  • Release: We will release a security update
  • Disclosure: We will publicly disclose the vulnerability after the fix is released

Coordinated Disclosure

Please allow time for the vulnerability to be fixed before public disclosure.

Security Best Practices

When contributing to Smykla Skalski projects:

  • Keep dependencies up to date
  • Never commit secrets, credentials, or API keys
  • Use environment variables for sensitive configuration
  • Follow the principle of least privilege
  • Review code changes for security implications

Acknowledgments

We appreciate the security research community's efforts to responsibly disclose vulnerabilities.

There aren't any published security advisories