Skip to content

Security: tadeasf/pspcz_analyzer

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, report them privately using GitHub's security advisory feature:

  1. Go to the Security tab of the repository.
  2. Select AdvisoriesReport a vulnerability.
  3. Fill in the advisory form and submit.

This opens a private draft advisory visible only to the maintainers, so the details stay confidential until a fix is ready.

What to include

To help us triage quickly, please include as much of the following as possible:

  • The affected version (release tag, commit SHA, or "latest main"), and whether you are running via Docker or a native install.
  • Step-by-step instructions to reproduce the issue.
  • The expected impact / potential attack scenario (what an attacker could achieve).
  • Any suggested mitigations, if you have them.

Response expectations

  • We aim to acknowledge receipt within a few business days.
  • We will investigate and keep you informed of progress toward a fix.
  • We prefer to develop and release a fix before any public disclosure, and we are happy to coordinate a disclosure timeline with you and credit reporters who wish to be acknowledged.

Thank you for helping keep pspcz_analyzer and its users safe.

There aren't any published security advisories