Skip to content

Security: TailorAU/pact

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in the PACT specification or reference implementation, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please email security@tailor.au with:

  1. A description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact assessment
  4. Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Assessment: Within 1 week
  • Fix/Disclosure: Coordinated with reporter

Scope

This policy covers:

  • The PACT specification (this repository)
  • The reference implementation (Tailor)
  • JSON Schema definitions
  • Example code in this repository

Supported Versions

Version Supported
v0.4 (draft) Yes
v0.3 (stable) Yes
< v0.3 No

There aren’t any published security advisories