Skip to content

Security: logancsack/astrolabe

SECURITY.md

Security Policy

Supported Versions

Astrolabe is currently maintained on the latest main branch.

Reporting a Vulnerability

Please do not create a public GitHub issue for security vulnerabilities.

Instead:

  1. Use GitHub’s private vulnerability reporting flow from the repository Security tab when it is available.
  2. If that is unavailable, contact the maintainer privately through GitHub profile contact options.
  3. Include:
    • vulnerability description
    • reproduction steps
    • impact assessment
    • suggested fix (if known)

Response Targets

  • Initial acknowledgment: within 72 hours
  • Triage decision: within 7 days
  • Patch timeline: depends on severity and complexity

Disclosure

After a fix is available, coordinated public disclosure is encouraged.

There aren’t any published security advisories