Thank you for helping keep this project safe for everyone. This policy describes how to report security vulnerabilities and what you can expect when you do.
If you find a security vulnerability, please follow these steps:
- Do not disclose publicly: Do not open a public issue to report security vulnerabilities. Use the email below to report problems privately.
- Report via GitHub Private Vulnerability Reporting:
Use the "Report a vulnerability" button in the repo's Security tab:
https://github.com/Ageursilva/ageublog/security/advisories/new
Include the following details:
- Clear description of the vulnerability.
- Steps to reproduce the issue.
- Potential impact.
- Suggested fixes (optional).
We are committed to treating security reports with priority. Here is the expected timeline:
- Acknowledgment: Within 48 hours.
- Initial analysis: Within 7 business days.
- Fix planning: Depending on severity, it may take up to 30 days to implement and publish a fix.
We will keep you updated on the fix status when necessary.
After fixing a vulnerability, we will follow these steps:
- Publish a new version containing the fix.
- Update the community about the vulnerability and the fix, while avoiding disclosing details that could exploit the flaw before everyone has updated.
If you report a vulnerability that is confirmed and fixed, we will be happy to include your name (with your permission) in the project's acknowledgments.
Thank you for helping keep the project safe!