Skip to content

Security: JoshLuedeman/onramp

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release on the main branch is supported with security updates.

Version Supported
Latest βœ…

Reporting a Vulnerability

Do NOT open a public issue.

To report a security vulnerability, please use GitHub's private vulnerability reporting:

πŸ‘‰ Report a vulnerability

What to expect

  1. Acknowledgment β€” We will acknowledge receipt of your report within 48 hours.
  2. Initial assessment β€” We will provide an initial assessment within 7 days.
  3. Collaboration β€” We will work with you to understand and reproduce the issue.
  4. Disclosure timing β€” We will coordinate disclosure timing with you.
  5. Credit β€” You will be credited in the security advisory unless you prefer to remain anonymous.

Responsible Disclosure

We ask that you:

  • Give us reasonable time to address the vulnerability before disclosing publicly.
  • Act in good faith to avoid privacy violations, data destruction, or service disruption.
  • Do not access or modify data belonging to other users.

Thank you for helping keep OnRamp and its users safe.

There aren't any published security advisories