| Version | Supported |
|---|---|
| 1.x.x | ✅ |
Please report security vulnerabilities to security@opensin-code.org.
We aim to:
- Acknowledge receipt within 48 hours
- Provide initial assessment within 5 business days
- Release a fix within 30 days for critical issues
- Private disclosure — Email details to security@opensin-code.org
- Verification — We confirm and assess the impact
- Fix development — We develop and test a fix
- Coordinated release — We publish the fix and advisory simultaneously
This policy covers:
- SIN-Code-Security-Bundle core (cmd/, internal/, pkg/)
- All CLI tools and MCP integrations
- Dependencies managed via go.mod
Out of scope:
- Third-party integrations not maintained by OpenSIN-Code
- Issues in underlying Go standard library (report to Go team)
We credit reporters in our security advisories (with permission).