rdio-scanner/SECURITY.md

56 lines
1.5 KiB
Markdown

# Security Policy
## Supported Versions
Security updates are provided for the latest version of **rdio-scanner**.
Older versions may not receive patches unless the issue is critical.
## Reporting a Vulnerability
If you discover a security vulnerability, we appreciate your help in responsibly disclosing it.
**Please do NOT open a public GitHub issue.**
Instead, contact us privately at: **<rdio-scanner@saubeo.solutions>**
Include as much detail as possible:
- Steps to reproduce
- Impact assessment
- Affected versions
- Any proof-of-concept code (if applicable)
We will acknowledge your report within **72 hours**.
## Disclosure Process
1. We investigate the report and confirm the vulnerability.
2. We work with you (if needed) to understand the issue fully.
3. We prepare a fix and coordinate a release.
4. We publish a security advisory once the fix is available.
We aim to resolve validated security issues within **14 days**, depending on severity and complexity.
## Scope
This policy applies to:
- The rdio-scanner codebase
- Documentation
- Any related scripts or tooling included in the repository
It does **not** cover:
- Third-party dependencies
- External services or infrastructure not maintained by Saubeo Solutions
## Responsible Disclosure
We ask that you:
- Give us reasonable time to fix the issue before public disclosure
- Avoid actions that could harm users or data
- Follow ethical security research practices
We greatly appreciate your contribution to the safety and reliability of rdio-scanner.