Skip to content

Latest commit

 

History

History
15 lines (8 loc) · 957 Bytes

File metadata and controls

15 lines (8 loc) · 957 Bytes

Security Policy

As responsible open source project maintainers, we treat vulnerabilities and issues around privacy violations seriously. We're also all volunteers, so we ask for your patience and responsible disclosures.

Reporting Vulnerabilities or Privacy Issues

Vulnerabilities should be reported privately only to shane@punderthings.com, the organization owner. Please ensure to clearly explain the issue, along with steps to reproduce and the reason(s) why this should be treated as a vulnerability.

Coordinated Disclosure: 90 days

As an all-volunteer project, we will acknowledge any valid security vulnerabilities as soon as possible. We also ask that you give us up to 90 days before making any public disclosures.

Resources

A great place to learn about responsible security processes is the OWASP Vulnerability Disclosure Cheat Sheet.