Skip to content

Security: SSbit01/secure-otp-server

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security issue, please report it privately first.

Private Disclosure (Strongly Recommended)

Some forks or deployments of this template may be running in production environments. To avoid exposing users to unnecessary risk, do not open a public GitHub issue for security vulnerabilities.

Instead, please contact me directly:

When reporting, please include:

  • A clear description of the vulnerability
  • Potential impact
  • Any suggested fixes or patches

You will receive an acknowledgment as soon as possible, and we will work together to verify and address the issue.

Public Disclosure

After the vulnerability has been fixed and users have had reasonable time to update, you may publicly disclose the issue if you wish. If you want attribution in release notes or advisories, feel free to request it.

Scope

This policy applies to this repository, but it does not automatically apply to third‑party forks, although private reporting is still encouraged to avoid harming downstream users.

Responsible Conduct

Please avoid:

  • Running automated scanners that may cause disruption
  • Exploiting vulnerabilities beyond what is necessary to demonstrate the issue

Thank you for your cooperation!

There aren’t any published security advisories