Skip to content

Security: marco-quicula/discloud-api-action

SECURITY.md

πŸ”’ Security Policy

πŸ›  Supported Versions

We support the latest stable version of this project. Older versions may not receive updates unless explicitly stated.

Version Supported
Latest βœ…
Others ❌

πŸ”„ Vulnerability SLA Table

We address vulnerabilities based on their severity within the following timeframes:

Severity SLA (days)
Critical 30
High 60
Medium 90
Low 120

🐞 Reporting Security Issues

The security of this repository is a top priority. We value the efforts of our contributors and community members to responsibly disclose vulnerabilities, and we are committed to addressing them promptly.

πŸ“¬ How to Report a Security Issue

  • Please use the GitHub Security Advisory tool:
    πŸ“ Report a Vulnerability.
  • Provide as much detail as possible, including steps to reproduce the issue and any relevant context.

Once we receive your report:

  1. πŸ“¨ Acknowledgment: We will acknowledge your submission and provide an initial response outlining the next steps.
  2. πŸ”„ Verification & Fix: Our security team will work diligently to verify the report, develop a fix, and communicate with you throughout the process.
  3. 🧩 Collaboration: You may be asked for additional information or guidance to help resolve the issue.

πŸ”„ Periodic Vulnerability Analysis

We maintain periodic vulnerability analysis via SNYK to ensure the ongoing security of the project.

πŸ”§ Dependency Updates

If any third-party module used has its vulnerability corrected, we will execute dependency updates according to the severity SLA.

πŸ”— Third-Party Modules

If the issue is related to a third-party module or dependency, we recommend reporting it directly to the maintainer of that module.

🀝 Commitment to Security

We are dedicated to maintaining a secure and reliable repository. Community involvement is vital, and we appreciate all contributions that help identify, fix, or prevent security issues.

For general security tips or feedback, feel free to contribute through our πŸ“œ CONTRIBUTING.md guidelines.

πŸ“š Additional Resources

Thank you for helping us improve the security and robustness of this project! πŸš€

There aren't any published security advisories