Krameff Solutions Ltd takes the security of our infrastructure automation and compliance tooling seriously. Given our focus on CIS Benchmark and DISA STIG compliant automation (including Ansible-Lockdown), we appreciate the community's help identifying issues responsibly.
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them by emailing security@krameff.com. Where possible, please include:
- A description of the vulnerability and its potential impact
- The affected repository, role/playbook, and version/commit
- Step-by-step instructions to reproduce the issue
- Any proof-of-concept code, logs, or screenshots
If a repository supports GitHub Private Vulnerability Reporting, you may also use the Security tab on that repository instead.
- Acknowledgement within 3 business days.
- We will investigate and keep you updated on progress at least every 7 days until resolved.
- Once a fix is available, we will coordinate a disclosure timeline with you and credit you (if desired) in the release notes.
Unless a specific repository's SECURITY.md states otherwise, only the latest released version (and the default branch) of a project receives security fixes.
This policy covers repositories owned by the krameff GitHub organization. Vulnerabilities in third-party dependencies should be reported to the upstream project, though we're happy to help coordinate if it affects our users.
Thank you for helping keep our automation and our users' infrastructure secure.