Skip to content

Security: cameronsjo/bosun

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest Yes
< latest No

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, use GitHub Private Security Advisories to report vulnerabilities.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

Stage Timeline
Acknowledgment 48 hours
Initial assessment 7 days
Fix and disclosure 30 days

Disclosure Policy

We follow coordinated disclosure. Once a fix is available, we will:

  1. Release a patched version
  2. Publish a security advisory
  3. Credit the reporter (unless anonymity is requested)

There aren’t any published security advisories