Skip to content

Security: pfederi/pragmaticux

.github/SECURITY.md

Security Policy

Supported Versions

We actively support the following versions with security updates:

Version Supported
2.0.x
< 2.0

Reporting a Vulnerability

If you discover a security vulnerability in Pragmatic UX Design, please help us by reporting it responsibly.

How to Report

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by emailing: patrick.federi@ergon.ch

What to Include

Please include the following information in your report:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact and severity
  • Any suggested fixes or mitigations
  • Your contact information for follow-up

Our Response Process

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours
  2. Investigation: We will investigate the issue and determine its validity
  3. Updates: We will keep you informed of our progress
  4. Resolution: We will work to resolve valid security issues
  5. Disclosure: We will coordinate disclosure timing with you

Security Best Practices

  • Keep your dependencies updated
  • Use HTTPS for all communications
  • Validate and sanitize user inputs
  • Implement proper authentication and authorization
  • Regularly audit your code and infrastructure

Responsible Disclosure

We kindly ask that you:

  • Give us reasonable time to fix the issue before public disclosure
  • Avoid accessing or modifying user data
  • Don't perform DoS attacks or degrade service performance
  • Don't spam our systems with automated vulnerability scanners

Recognition

We appreciate security researchers who help keep our users safe. With your permission, we may publicly acknowledge your contribution to our security.

Contact

For security-related questions or concerns:

There aren’t any published security advisories