Skip to content

Latest commit

 

History

History
39 lines (27 loc) · 1.07 KB

File metadata and controls

39 lines (27 loc) · 1.07 KB

Security Disclosure

Scope

Use this process for vulnerabilities, secrets exposure, unsafe defaults, privilege escalation paths, insecure examples or supply-chain concerns identified in Seppmail-API-PowerShell.

Do not post publicly

Do not open a public issue for:

  • working exploit details
  • customer-specific indicators
  • credentials, tokens, certificates or keys
  • screenshots that expose identities, tenants or endpoints

Recommended flow

  1. Prepare a short report with affected files, suspected impact and reproduction steps.
  2. Include remediation ideas when available.
  3. Use the contact and disclosure routes documented in SECURITY.md and SUPPORT.md.
  4. Coordinate a fix before public disclosure.

Triage dimensions

Evaluate reports against:

  • confidentiality impact
  • integrity impact
  • availability impact
  • exposure of privileged identities or administrative APIs
  • likelihood of accidental misuse by operators

Evidence suggestions

  • commit reference
  • affected example path
  • configuration fragment
  • expected secure behavior
  • observed insecure behavior