Skip to content

Security: GitHubSecurityLab/gh-secure

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Please do NOT open a public GitHub issue for security vulnerabilities.

Instead, please report them via GitHub's private vulnerability reporting feature:

  1. Go to the Security tab of this repository.
  2. Click "Report a vulnerability".
  3. Fill in the details of the vulnerability.

Alternatively, you can email the GitHub Security Lab team at securitylab@github.com.

What to Include

When reporting a vulnerability, please include:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce the issue.
  • Any proof-of-concept code or output.
  • Your suggested fix (if any).

Response Timeline

We will acknowledge receipt of your report within 5 business days and aim to provide a resolution or mitigation plan within 30 days.

Scope

This policy applies to the code in this repository. For vulnerabilities in dependencies, please report them to the respective upstream projects.

There aren't any published security advisories