Security is a core part of how Angelito Systems builds software.
- Supported scope
- Reporting a vulnerability
- What to include
- What to avoid
- Responsible disclosure
- Safe harbor
This policy applies to repositories and products maintained under the Angelito Systems organization. Vulnerabilities in third-party dependencies should be reported to the maintainers of that dependency, though we're glad to be notified as well.
Please do not disclose exploitable vulnerabilities in public issues, discussions or pull requests.
Use the repository's configured private security reporting channel when available (e.g. GitHub's private vulnerability reporting). If none is configured yet, contact the project maintainers through an officially published contact method.
We aim to acknowledge reports as promptly as we can and will keep you updated as the investigation progresses.
- Affected repository and version.
- A clear description of the issue.
- Reproduction steps or a proof of concept.
- Impact assessment.
- Suggested mitigation, if known.
Please avoid including personal data, production credentials or active secrets in reports. If you accidentally do, let us know so we can help you rotate them.
We ask security researchers to allow reasonable time for investigation and remediation before any public disclosure, and to make a good-faith effort to avoid privacy violations, data destruction and service disruption during their research.
We consider security research conducted in good faith, consistent with this policy, to be authorized. We will not pursue legal action against researchers who follow responsible disclosure practices described here.