Skip to content

Security: epikodelabs/.github

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report suspected security vulnerabilities in public GitHub issues or Discussions.

If GitHub Private Vulnerability Reporting is enabled for the affected repository, use it.

Otherwise, contact the EpikodeLabs maintainers privately and include:

  • the affected project and version or commit;
  • a description of the vulnerability;
  • reproduction steps or proof of concept when available;
  • the expected security impact;
  • any known mitigations.

Please avoid accessing, modifying, or exposing data that is not yours while investigating a vulnerability.

Response

We will try to:

  1. acknowledge a valid report;
  2. reproduce and assess the issue;
  3. determine affected versions;
  4. prepare a fix or mitigation;
  5. coordinate disclosure when appropriate.

Response times may vary because EpikodeLabs is a small open-source organization.

Supported versions

Unless a repository documents a different policy, security fixes are generally targeted at the latest actively maintained release line.

Older releases may not receive patches.

Public disclosure

Please allow maintainers a reasonable opportunity to investigate and fix a vulnerability before publishing details that could put users at risk.

We appreciate responsible security research and clear reports.

There aren't any published security advisories