Skip to content

Security: DevToolie/Paragent

SECURITY.md

Security Policy

Supported versions

We actively support the latest release of each public DevToolie project. Older versions may not receive security fixes.

Version Supported
Latest release Yes
Prior major Case-by-case
Unreleased / main Best-effort

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, email siddharthmehta0906@gmail.com with:

  • A clear description of the vulnerability
  • Steps to reproduce (PoC if possible)
  • Impact assessment (what an attacker could achieve)
  • Affected repository / package / version
  • Any suggested remediation

If the repository has GitHub private vulnerability reporting enabled, you may also use that.

What to expect

Step Target
Acknowledgement within 3 business days
Initial assessment within 7 business days
Fix / advisory timeline communicated after triage

We will keep you informed of progress and credit you in any advisory (unless you prefer to remain anonymous).

Safe harbor

We consider good-faith security research conducted within this policy to be authorized. We will not pursue legal action against researchers who:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service interruption
  • Do not access or modify data beyond what is needed to demonstrate the issue
  • Report findings promptly and privately
  • Give us reasonable time to remediate before public disclosure

Preferential disclosure

Please do not publicly disclose the issue until we have shipped a fix or agreed on a coordinated disclosure date.

There aren't any published security advisories