Skip to content

Security: felipe-veas/dotctl

.github/SECURITY.md

Security Policy

Supported Versions

This project is actively maintained on the latest stable release lines.

Version Supported
1.7.x
1.6.x
< 1.6.0

If a version line is not listed above, it is considered unsupported for security updates.

Reporting a Vulnerability

Please do not report security issues in public GitHub issues or pull requests.

Use GitHub Private Vulnerability Reporting:

When possible, include:

  • Affected version(s)
  • Reproduction steps or proof of concept
  • Expected impact and threat model
  • Any known mitigations

Response and disclosure process

  • Initial acknowledgment target: within 72 hours
  • Triage update target: within 7 days
  • Regular status updates: at least every 7 days until resolution
  • Fix timeline target:
    • Critical/High: as soon as possible, typically within 14 days
    • Medium/Low: best effort, typically within 30 days

After a fix is available, we will coordinate disclosure and publish a patched release.

There aren’t any published security advisories