Skip to content

Security: Ankit5125/.github

Security

SECURITY.md

Security Policy

The security of Plizent projects is important to us.

This document explains how to report security vulnerabilities and what you can expect after submitting a report.

If you discover a security vulnerability, please report it privately so we can investigate and resolve the issue before it is publicly disclosed.


Supported Versions

Unless stated otherwise, only the latest maintained version of each project receives security updates.

Some repositories may define their own support policy or supported versions. When available, follow the repository-specific security documentation instead of this guide.


Reporting a Vulnerability

Warning

Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

If the affected repository supports GitHub Private Vulnerability Reporting, use it to submit your report.

If Private Vulnerability Reporting is not available, follow the repository's documented security contact or reporting process.

When reporting a vulnerability, please include:

  • A clear description of the issue.
  • The affected project and version, if known.
  • Steps to reproduce the issue.
  • The potential impact.
  • A proof of concept, if available.
  • Suggested mitigations or fixes, if known.

Providing complete information helps us investigate and resolve security issues more efficiently.


Response Process

After receiving a vulnerability report, we will:

  1. Acknowledge receipt of the report.
  2. Review and validate the reported vulnerability.
  3. Assess its impact and affected projects.
  4. Develop, test, and prepare a fix, when applicable.
  5. Coordinate responsible disclosure.
  6. Publish a security advisory, when appropriate.

Note

Response times may vary depending on the severity, complexity, and impact of the reported vulnerability.


Responsible Disclosure

We ask that you:

  • Give us a reasonable amount of time to investigate and address the issue.
  • Avoid publicly disclosing vulnerability details until a fix or mitigation is available.
  • Act in good faith throughout the disclosure process.

Responsible disclosure helps protect users while we investigate, develop, and release a fix.


Scope

This document provides the default security policy for Plizent repositories.

Some repositories may include additional security documentation or repository-specific reporting instructions.

When repository-specific security documentation is available, follow that documentation instead of this guide.


Acknowledgements

We appreciate everyone who responsibly reports security vulnerabilities and helps improve the security of Plizent projects.

Thank you for helping make Plizent more secure.


Security Best Practices

You can help improve the security of Plizent projects by following these practices:

  • Keep your project dependencies up to date.
  • Never commit secrets, credentials, or private keys.
  • Validate and sanitize untrusted input.
  • Use supported versions of the project whenever possible.
  • Report suspected security vulnerabilities promptly through the appropriate reporting channel.

These practices help reduce security risks and contribute to a safer experience for everyone.

There aren't any published security advisories