Skip to content

Security: edithatogo/humanizer-next

SECURITY.md

Security Policy

Reporting a Vulnerability

We take the security of Humanizer seriously. If you believe you've found a security vulnerability, please follow these guidelines:

How to Report

Preferred Method: Use GitHub's private vulnerability reporting feature:

  1. Go to the Security tab
  2. Click "Report a vulnerability"
  3. Provide details about the vulnerability

Alternative Method: If you cannot use GitHub's feature, you may create an issue with the [security] label prefix, but note that this will be publicly visible.

What to Include

Please provide as much information as possible:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 5 business days
  • Resolution Target: Depends on severity (see below)

Severity Levels

Severity Response Time Resolution Target
Critical 24 hours 7 days
High 48 hours 14 days
Medium 5 days 30 days
Low 10 days Next release

What to Expect

  1. Acknowledgment: We'll confirm receipt of your report within 48 hours
  2. Assessment: Our team will evaluate the vulnerability and determine severity
  3. Communication: We'll keep you informed of our progress
  4. Resolution: Once fixed, we'll notify you and optionally credit you (with your permission)

Supported Versions

Version Supported
2.3.x ✅ Yes
2.2.x ✅ Yes
< 2.2 ❌ No

Security Best Practices for Users

While we work to keep Humanizer secure, please also follow these best practices:

  1. Keep Updated: Always use the latest version
  2. Review Permissions: Only grant necessary tool access
  3. Validate Input: Be cautious with untrusted text input
  4. Report Issues: Don't hesitate to report potential vulnerabilities

Security Research

We welcome responsible security research. If you're conducting security research on Humanizer:

  • Please coordinate with us first
  • Avoid testing on production systems
  • Respect user privacy and data

Last Updated: 2026-03-03

Contact: For security questions, please use the vulnerability reporting system above.

There aren’t any published security advisories