Skip to content

Security: HeMaNtMoRee/repognition

Security

SECURITY.md

Security Policy for Repo-gnition

The Repo-gnition team and community take the security of our project seriously. We appreciate the efforts of security researchers and our user community in helping us maintain a secure codebase.

Supported Versions

We are committed to providing security updates for the following versions:

Version Supported
0.1.x
< 0.1

Reporting a Vulnerability

We have a responsible disclosure policy. Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them directly to the project maintainer. To make a report, please take one of the following actions:

  1. Open a Private Security Advisory: The preferred method is to use GitHub's private vulnerability reporting feature. You can do this by going to the "Security" tab of the repository and clicking "Report a vulnerability." This ensures the report is private and tracked securely.

  2. Email the Maintainer: If you are unable to use GitHub's advisory system, please email the project maintainer directly using the contact information on their GitHub profile.

What to Include in Your Report

To help us resolve the issue as quickly as possible, please provide a detailed report including:

  • A clear description of the vulnerability and its potential impact.

  • The version of the project affected.

  • Detailed steps to reproduce the vulnerability. This could include code snippets, proof-of-concept exploits, or a description of the setup.

  • Any potential mitigations or workarounds you are aware of.

Our Commitment

When you report a vulnerability, we will make every effort to:

  1. Acknowledge your report within 48 hours.

  2. Provide an initial assessment of the vulnerability's severity and impact within 72 hours.

  3. Keep you informed of our progress as we work on a fix.

  4. Publicly credit you for your discovery (unless you prefer to remain anonymous) once the vulnerability has been patched and a new version is released.

We are committed to addressing all security issues in a timely and responsible manner. Thank you for helping keep Repo-gnition secure.

There aren’t any published security advisories