Skip to content

Security: UglyEgg/crushr

Security

SECURITY.md

Security Policy

This repository is continuously scanned for secrets using TruffleHog. All commits and pull requests are automatically checked for credential leaks.

Reporting a vulnerability

If you believe you have found a security vulnerability in this project, please do not open a public issue.

Instead, report it privately to the maintainer through the contact method published in this repository profile or project website.

Please include:

  • a clear description of the issue
  • affected component(s)
  • reproduction steps or proof of concept, if available
  • impact assessment, if known

Disclosure

This project is under active development. Reported vulnerabilities will be reviewed and triaged as time permits. Coordinated disclosure is preferred until a fix or mitigation is available.

Scope

Security reports should be limited to genuine vulnerabilities. General bugs, correctness issues, feature requests, and support questions should be filed through the normal public issue process unless they have direct security impact.

Product security documentation

Repository vulnerability handling is only one part of the project security story. The product security and assurance set lives under docs/security/.

That set is maintained as a self-assessed design alignment against relevant ISO/IEC 27001 control principles for this project’s scope. It is not a certification statement.

There aren't any published security advisories