Skip to content

Security: Ageursilva/ageublog

SECURITY.md

Security Policy

Thank you for helping keep this project safe for everyone. This policy describes how to report security vulnerabilities and what you can expect when you do.

Reporting Security Issues

If you find a security vulnerability, please follow these steps:

  1. Do not disclose publicly: Do not open a public issue to report security vulnerabilities. Use the email below to report problems privately.
  2. Report via GitHub Private Vulnerability Reporting: Use the "Report a vulnerability" button in the repo's Security tab: https://github.com/Ageursilva/ageublog/security/advisories/new Include the following details:
    • Clear description of the vulnerability.
    • Steps to reproduce the issue.
    • Potential impact.
    • Suggested fixes (optional).

Response Time

We are committed to treating security reports with priority. Here is the expected timeline:

  1. Acknowledgment: Within 48 hours.
  2. Initial analysis: Within 7 business days.
  3. Fix planning: Depending on severity, it may take up to 30 days to implement and publish a fix.

We will keep you updated on the fix status when necessary.

Vulnerability Disclosure

After fixing a vulnerability, we will follow these steps:

  1. Publish a new version containing the fix.
  2. Update the community about the vulnerability and the fix, while avoiding disclosing details that could exploit the flaw before everyone has updated.

Acknowledgments

If you report a vulnerability that is confirmed and fixed, we will be happy to include your name (with your permission) in the project's acknowledgments.

Thank you for helping keep the project safe!

There aren't any published security advisories