Skip to content

Security: zircote/Hal

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest Yes

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Please do NOT open a public GitHub issue for security vulnerabilities.

Instead, please send an email to the project maintainers at security@zircote.com with:

  1. A description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact assessment
  4. Any suggested fixes (if applicable)

Response Timeline

  • Acknowledgment: Within 48 hours of receipt
  • Initial assessment: Within 5 business days
  • Resolution target: Within 30 days for confirmed vulnerabilities

Disclosure Policy

We follow coordinated disclosure. We ask that you:

  1. Allow us reasonable time to address the issue before public disclosure
  2. Make a good-faith effort to avoid privacy violations, data loss, and service disruption
  3. Do not exploit the vulnerability beyond what is necessary to demonstrate it

Recognition

We appreciate the efforts of security researchers. Contributors who report valid vulnerabilities will be acknowledged (with permission) in our release notes.

There aren’t any published security advisories