Skip to content

Security: krameff/.github

Security

SECURITY.md

Security Policy

Krameff Solutions Ltd takes the security of our infrastructure automation and compliance tooling seriously. Given our focus on CIS Benchmark and DISA STIG compliant automation (including Ansible-Lockdown), we appreciate the community's help identifying issues responsibly.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, report them by emailing security@krameff.com. Where possible, please include:

  • A description of the vulnerability and its potential impact
  • The affected repository, role/playbook, and version/commit
  • Step-by-step instructions to reproduce the issue
  • Any proof-of-concept code, logs, or screenshots

If a repository supports GitHub Private Vulnerability Reporting, you may also use the Security tab on that repository instead.

What to expect

  • Acknowledgement within 3 business days.
  • We will investigate and keep you updated on progress at least every 7 days until resolved.
  • Once a fix is available, we will coordinate a disclosure timeline with you and credit you (if desired) in the release notes.

Supported versions

Unless a specific repository's SECURITY.md states otherwise, only the latest released version (and the default branch) of a project receives security fixes.

Scope

This policy covers repositories owned by the krameff GitHub organization. Vulnerabilities in third-party dependencies should be reported to the upstream project, though we're happy to help coordinate if it affects our users.

Thank you for helping keep our automation and our users' infrastructure secure.

There aren't any published security advisories