Skip to content

Security: rdmarsh/elm

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.3.0
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.1.0
1.0.6
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
< 1.0

Reporting a Vulnerability

For sensitive bugs like security vulnerabilities, please contact rdmarsh@gmail.com directly or use githubs vulnerability reporting function instead of the issue tracker. We appreciate your effort to improve the security and privacy of this project!

Responsible Disclosure Guidelines

Please follow these guidelines when reporting security vulnerabilities:

  1. Keep it Confidential: Do not disclose the vulnerability publicly until it has been addressed.

  2. Provide Clear Details: When reporting a vulnerability, include as much detail as possible, such as:

    • Description of the vulnerability
    • Steps to reproduce the issue
    • Impact assessment (what data could be affected, etc.)
  3. Be Respectful: Understand that security vulnerabilities can have significant implications. Please be courteous in your communications.

  4. Use the Correct Channels: Report vulnerabilities through the specified contact methods (email or GitHub’s reporting function) to ensure they are received promptly.

  5. No Exploitation: Do not exploit the vulnerability or attempt to gain unauthorised access to systems, accounts, or data.

  6. Give Us Time: Allow us a reasonable time frame to investigate and address the issue before making any public disclosures.

  7. Stay Engaged: Feel free to follow up if you don’t receive an acknowledgement within a few days.

By following these guidelines, you help us maintain the security and integrity of our project. Thank you for your cooperation!

There aren’t any published security advisories