Skip to content

Latest commit

 

History

History
37 lines (23 loc) · 1.1 KB

File metadata and controls

37 lines (23 loc) · 1.1 KB

Security Policy

Supported Versions

Version Supported
Latest
< Latest

Only the most recent release receives security updates.

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

Instead, use GitHub Private Vulnerability Reporting to submit your report confidentially.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

What to expect

  • Acknowledgement within 72 hours
  • Status update within 7 days with an initial assessment
  • Coordinated disclosure — we will work with you to agree on a disclosure timeline, typically 90 days from the initial report

Scope

This policy covers the Scriptoria codebase and its official distribution channels. Third-party dependencies should be reported to their respective maintainers.

Preferred Languages

We accept vulnerability reports in English or Italian.