Skip to content

Security: rumba-id/.github

Security

SECURITY.md

Security Policy

Rumba takes security seriously. This document explains how to report vulnerabilities.

Reporting a Vulnerability

For Repository-Specific Issues

  1. Go to the specific repository
  2. Click the Security tab
  3. Select Report a vulnerability
  4. Fill out the form with details

GitHub's private vulnerability reporting keeps your report confidential until a fix is available.

What to Include

  • Description of the vulnerability
  • Steps to reproduce (if applicable)
  • Potential impact
  • Suggested fix (optional)

For Third-Party Dependencies

Report security issues in dependencies directly to their maintainers.

Our Response

When you report a security issue:

  • We acknowledge receipt within 48 hours
  • We provide status updates as we investigate
  • We credit reporters in security advisories (unless you prefer anonymity)
  • We coordinate disclosure timing with you

Alternative Contact

For issues that cannot be reported through GitHub, or for coordinated disclosure discussions:

Scope

This policy covers:

  • The Rumba identity platform
  • Official container images
  • Documentation that could lead to security issues

Out of scope:

  • Third-party integrations not maintained by us
  • Issues in dependencies (report to upstream)
  • Social engineering attacks
  • Physical security

Responsible Disclosure

We ask that you:

  • Give us reasonable time to address issues before public disclosure
  • Avoid accessing or modifying user data
  • Act in good faith to avoid privacy violations and service disruption

We will not pursue legal action against researchers who follow these guidelines.

There aren’t any published security advisories