| Version | Supported |
|---|---|
| 0.1.x | ✅ |
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report them via email to:
- Primary: [email protected]
- Secondary: [email protected]
Include the following information:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 5 business days
- Status updates: Weekly until resolved
Our repository includes:
- Automated dependency vulnerability scanning (Dependabot)
- SAST scanning with Ruff security rules
- SBOM generation and vulnerability analysis (Syft + Grype)
- OpenSSF Scorecard security assessment
We follow responsible disclosure:
- Vulnerabilities are fixed before public disclosure
- Credit given to reporters (unless anonymity requested)
- Security advisories published for confirmed issues