Skip to content

Security: rewse/dotfiles

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously. If you believe you have found a security vulnerability, please report it to us as described below.

How to Report

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them using GitHub's Security Advisory feature:

  1. Go to the repository's "Security" tab
  2. Click "Report a vulnerability"
  3. Fill in the details of the vulnerability
  4. Submit the report

What to Include

Please include the following information in your report:

  • Type of issue (e.g., credential exposure, arbitrary code execution, etc.)
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

Response Timeline

  • We will acknowledge receipt of your vulnerability report within 3 business days
  • We will provide a more detailed response within 7 business days indicating the next steps
  • We will keep you informed of the progress towards a fix and full announcement
  • We may ask for additional information or guidance

Disclosure Policy

When we receive a security bug report, we will:

  1. Confirm the problem and determine affected versions
  2. Audit code to find similar problems
  3. Prepare fixes for all supported versions
  4. Release new versions as soon as possible
  5. Publish a security advisory on GitHub

There aren’t any published security advisories