Skip to content

Security: Omnifolio-app/sec-toolkit

Security

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this package, please report it responsibly.

DO NOT open a public GitHub issue for security vulnerabilities.

How to Report

  1. Email: security@omnifolio.app
  2. Include a description of the vulnerability
  3. Include steps to reproduce if possible
  4. We will acknowledge receipt within 48 hours

Scope

This package interacts with the SEC EDGAR public API. Security concerns may include:

  • Injection vulnerabilities in HTML/XML parsing
  • Denial of service through malformed input
  • Information disclosure through error messages

Response Timeline

  • 48 hours: Acknowledgement
  • 7 days: Initial assessment
  • 30 days: Fix release (for confirmed vulnerabilities)

Supported Versions

Version Supported
1.x
< 1.0

There aren't any published security advisories