Skip to content

Security: aaronmallen/sai

docs/SECURITY.md

Security Policy

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please bring it to our attention right away!

Reporting Process

Please DO NOT file a public issue. Instead, report security vulnerabilities through GitHub's private vulnerability reporting feature.

Your report should include:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Suggested fix (if any)

What to Expect

After you've submitted your report:

  1. You'll receive an acknowledgment within 24 hours
  2. We'll investigate and keep you updated on our findings
  3. Once we've determined the impact and resolution:
  • We'll patch the vulnerability
  • We'll make an announcement to the community if warranted
  • You'll be credited for the discovery (unless you prefer to remain anonymous)

Disclosure Policy

When we receive a security bug report, we will:

  1. Confirm the problem and determine affected versions
  2. Audit code to find any similar problems
  3. Prepare fixes for all supported versions
  4. Release patches as soon as possible

Comments on this Policy

If you have suggestions on how this process could be improved, please submit a pull request.

Supported Versions

Version Support
0.4.0
`> 0.4.0'

Key

Symbol Meaning
Supported
Not Supported
🧪 Experimental
🚧 In Development

There aren’t any published security advisories