Skip to content

Security: briza-insurance/illogical

SECURITY.md

Security Policy

What Constitutes a Vulnerability

A security vulnerability is a flaw in the software that could be exploited to compromise the integrity, availability, or confidentiality of the system or data. We take all vulnerabilities seriously and appreciate your efforts to responsibly disclose any issues you find.

Reporting a Vulnerability

If you discover a security vulnerability within this project, please report it securely so that the information is not publicly visible.

Do not open a public issue.

To report a security issue, please use the GitHub Security Advisory feature. Navigate to the Security tab of this repository, select Advisories, and click Report a vulnerability (you can also use this direct link: https://github.com/briza-insurance/illogical/security/advisories/new). Please provide a detailed description of the issue, the steps required to reproduce it, affected versions, and any known mitigations.

Vulnerability Disclosure Process

We follow coordinated vulnerability disclosure guidelines to respond to vulnerability disclosures. Our process is as follows:

  1. We will acknowledge receipt of your vulnerability report within 7 days.
  2. We will investigate the issue and determine its validity and severity.
  3. We aim to implement a fix and coordinate the public disclosure within 90 days of the initial report, depending on the complexity of the issue.

Thank you for helping keep our project secure and safe for everyone.

There aren't any published security advisories