Skip to content

Security: baidu/nettools

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take the security of nettools seriously. If you believe you have found a security vulnerability, please report it to us as described below.

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via GitHub Security Advisories at:

https://github.com/baidu/nettools/security/advisories/new

You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

Please include the following information:

  • Type of vulnerability
  • Full paths of source file(s) related to the vulnerability
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

Preferred Languages

We prefer all communications to be in English or Chinese.

Disclosure Policy

When we receive a security bug report, we will:

  1. Confirm the problem and determine the affected versions
  2. Audit code to find any similar problems
  3. Prepare fixes for all supported versions
  4. Release patches and publish a security advisory

Comments on this Policy

If you have suggestions on how this process could be improved, please submit a pull request.

There aren't any published security advisories