rdio-scanner/SECURITY.md

1.5 KiB

Security Policy

Supported Versions

Security updates are provided for the latest version of rdio-scanner.
Older versions may not receive patches unless the issue is critical.

Reporting a Vulnerability

If you discover a security vulnerability, we appreciate your help in responsibly disclosing it.

Please do NOT open a public GitHub issue.

Instead, contact us privately at: rdio-scanner@saubeo.solutions

Include as much detail as possible:

  • Steps to reproduce
  • Impact assessment
  • Affected versions
  • Any proof-of-concept code (if applicable)

We will acknowledge your report within 72 hours.

Disclosure Process

  1. We investigate the report and confirm the vulnerability.
  2. We work with you (if needed) to understand the issue fully.
  3. We prepare a fix and coordinate a release.
  4. We publish a security advisory once the fix is available.

We aim to resolve validated security issues within 14 days, depending on severity and complexity.

Scope

This policy applies to:

  • The rdio-scanner codebase
  • Documentation
  • Any related scripts or tooling included in the repository

It does not cover:

  • Third-party dependencies
  • External services or infrastructure not maintained by Saubeo Solutions

Responsible Disclosure

We ask that you:

  • Give us reasonable time to fix the issue before public disclosure
  • Avoid actions that could harm users or data
  • Follow ethical security research practices

We greatly appreciate your contribution to the safety and reliability of rdio-scanner.