SECURITY.md

b2f3bce0c254e11c4a7e871c3bb844a09c53a96e
hutch/SECURITY.md rendered · source · history · blame · raw

33 lines · 947 bytes

Security Policy

Supported Versions

Version Supported
2.x ✅ Yes
< 2.0 ❌ No

Reporting a Vulnerability

If you discover a security vulnerability, do not open a public issue. Instead:

  1. Email your report to security@cleberg.net. Include:
  • A detailed description of the vulnerability
  • Steps to reproduce
  • Any relevant context (e.g., affected versions, environment)
  1. Response Time: We will acknowledge your report within 3 business days and keep you updated on the progress.
  2. Resolution: If confirmed, we will:
  • Provide an estimated timeline for a fix
  • Work with you to verify the resolution
  • Credit you for the discovery (if you wish)
  1. Declined Reports: If the report is invalid or out of scope, we will explain why and close the issue.

Thank you for helping improve the security of our project!