Skip to content

Security: Deathcharge/samsarix-platform

SECURITY.md

Security policy

Supported versions

Samsarix Platform Doctor is currently a 0.2.x pre-release. Security fixes are made on the latest supported release line and the default branch. Older pre-release snapshots may not receive fixes.

Report a vulnerability privately

Email support@samsarix.com with the subject Security: Samsarix Platform Doctor. Do not open a public issue for an unpatched vulnerability and do not include live credentials, personal data, or production secrets.

Include, when possible:

  • the affected version or commit;
  • the operating system and Python version;
  • reproducible steps or a minimal manifest;
  • the security impact and attacker prerequisites;
  • any suggested mitigation;
  • how you would like to be credited.

GitHub private vulnerability reporting may also be used when it is enabled for this repository. Samsarix LLC will coordinate validation, remediation, and disclosure with the reporter. Please allow time for a fix before publishing exploit details.

Scope

Reports about secret disclosure, path containment, unsafe file creation, dependency or release integrity, and denial of service from crafted manifests are in scope. General support requests belong at support@samsarix.com or in a public issue after sensitive data has been removed.

There aren't any published security advisories