Skip to content

Security: AditiGupta-tech/neonest

Security

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it privately so we can address it responsibly.

Contact Options

⚠️ Please do not open a public issue for security problems.


What to Include in Your Report

When reporting, please provide:

  • A clear description of the vulnerability.
  • Steps to reproduce the issue.
  • Expected vs. actual behavior.
  • Any relevant logs, files, or screenshots.
  • Your contact information (so we can follow up).

Our Response

  • We will acknowledge your report within 3 business days.
  • We will investigate and keep you updated on progress.
  • A fix or patch will be released as quickly as possible.
  • We will coordinate disclosure with you before making any public announcements.

Severity Levels

  • Low – Minor bug, no sensitive data exposed.
  • Medium – Limited data exposure or low-impact flaw.
  • High – Potential data leak or bypass of security controls.
  • Critical – Remote code execution, credential leaks, or severe vulnerabilities.

Safe Harbor

If you follow this policy and report vulnerabilities responsibly:

  • We will not pursue legal action.
  • We will treat your report with respect and confidentiality.

Scope

This policy applies to the code and resources in this repository only.
Third-party dependencies and external services are out of scope.

There aren’t any published security advisories