Skip to content

Security: neural-garage/tools

Security

SECURITY.md

Security Policy

Supported Versions

Neural Garage takes security seriously. We support the following versions:

Tool Version Supported
bury 0.1.x

Reporting a Vulnerability

If you discover a security vulnerability within any Neural Garage tools, please follow these steps:

Private Disclosure

  1. DO NOT open a public issue
  2. Email security details to the maintainers (use GitHub Security Advisories)
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

What to Expect

  • Acknowledgment: Within 48 hours
  • Initial Assessment: Within 1 week
  • Fix Timeline: Depends on severity
    • Critical: Within 7 days
    • High: Within 30 days
    • Medium/Low: Next release cycle

Disclosure Policy

  • We will work with you to understand and address the issue
  • We will credit you in the security advisory (unless you prefer to remain anonymous)
  • We will coordinate public disclosure timing with you
  • Security fixes will be released as soon as possible

Security Best Practices

When using Neural Garage tools:

  • Always use the latest version
  • Review generated reports before acting on them
  • Be cautious with automated fixes (coming in future versions)
  • Follow the principle of least privilege in CI/CD integrations

Bug Bounty

Currently, we do not have a bug bounty program, but we greatly appreciate responsible disclosure and will publicly acknowledge contributors.

Contact

For security-related concerns, please use GitHub's Security Advisory feature or contact the maintainers through GitHub.

There aren’t any published security advisories