Skip to content

Security: kashingl/ToolInventory

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
main
older branches

Reporting a Vulnerability

Please do not create a public issue for security vulnerabilities.

Report vulnerabilities privately to the repository owner through GitHub private reporting (if enabled) or a direct private channel.

Include:

  1. Affected area and impact.
  2. Reproduction steps or proof of concept.
  3. Suggested remediation (if available).

Response Targets

  1. Initial acknowledgement: within 3 business days.
  2. Triage and severity assessment: within 7 business days.
  3. Fix timeline: based on severity and exploitability.

Disclosure

After a fix is available, coordinated disclosure is preferred. Credit can be provided on request.

There aren't any published security advisories