Skip to content

Latest commit

 

History

History
36 lines (23 loc) · 1.01 KB

File metadata and controls

36 lines (23 loc) · 1.01 KB

Security Policy

Supported versions

This repository tracks standards and reusable CI workflows. Security fixes are applied on the default branch and included in the next release tag.

Version Supported
Latest release tag
Previous minor release
Older releases

Reporting a vulnerability

Do not open public issues for vulnerabilities.

Report privately using GitHub Security Advisories:

Include:

  • Affected files/workflows and branch or tag
  • Reproduction details or proof of concept
  • Expected vs actual security behavior
  • Impact and suggested remediation

Response targets

  • Initial acknowledgment: within 3 business days
  • Triage update: within 7 business days
  • Remediation timeline: based on severity and exploitability

Disclosure

After remediation is available, maintainers may publish a coordinated disclosure with impact, fix summary, and upgrade guidance.