Skip to content

Security: siiway/prism

SECURITY.md

Security Policy

If you discover a potential security issue in Prism, please report it responsibly and privately.

Reporting security vulnerabilities

Please do not open a public GitHub issue. Use GitHub Security Advisories (GHSA) so the report is handled privately and gets a proper advisory workflow:

  1. Go to the repository’s Security tab: https://github.com/siiway/prism/security/advisories
  2. Click Report a vulnerability (or New advisory).
  3. Provide:
    • Affected version(s) / commit
    • Reproduction steps
    • Impact and severity assessment
    • Possible exploit scenario and any proof-of-concept (redacted if needed)
    • Suggested fix, if available

Why GHSA

  • Reports submitted via GHSA are visible only to maintainers and the reporter during triage.
  • Confirmed vulnerabilities can be coordinated and published as a GitHub advisory with a GHSA-xxxx-xxxx-xxxx identifier.
  • This helps avoid premature disclosure and supports coordinated disclosure.

Disclosure policy

Please give us reasonable time to investigate and fix the issue before public discussion. We ask that you keep details private until we confirm a fix and publish advisory/patched release notes.

Expected timeline

We aim to acknowledge reports promptly and provide status updates as they become available.

There aren't any published security advisories