Skip to content

Security: eabusato/civitas

Security

SECURITY.md

Security Policy

Reporting

Do not open public issues for undisclosed vulnerabilities.

Report security issues privately to the maintainer with:

  • affected module or surface
  • reproduction steps
  • impact assessment
  • any suggested mitigation

Scope

Relevant reports include:

  • auth or session bypass
  • CSRF, host validation or request parsing flaws
  • secrets leakage
  • unsafe file, media or storage handling
  • unsafe admin or tracing exposure

Public fixes

After a fix is available, documentation and release notes should describe the impact and any required operator action.

There aren't any published security advisories