Skip to content

Security: FlashyLabs/conformance-kit

Security

SECURITY.md

Security

Reporting

Report a vulnerability privately through GitHub's Report a vulnerability button on this repository's Security tab. That opens a private advisory only the maintainers can read.

Do not open a public issue for a vulnerability, and do not send details to a mailing list or a chat channel.

What to expect

Acknowledgement within 3 working days
First assessment within 10 working days
Fix or a stated reason there will not be one within 90 days

If we miss one of those, say so publicly. A disclosure window nobody is held to is worse than none, because it asks a reporter to wait on a promise that was never load-bearing.

Scope

This repository's code and the documents it publishes. A vulnerability in a dependency belongs to that dependency; tell us anyway if it reaches users through us.

What is not a vulnerability here

A specification that permits something you consider unwise is a specification disagreement — open an issue, because that is a conversation worth having in public. A published file proving less than a reader assumes is the stated design: publishing a file at a domain proves that somebody can write to that host, and it never proves an organisation is who it says it is.

There aren't any published security advisories