Skip to content

Security: ghettovoice/timeutil

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest ✅

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Do not open a public issue for security vulnerabilities.

Instead, please send a detailed report to: ghettovoice@gmail.com

What to Include

  • A clear description of the vulnerability.
  • Steps to reproduce the issue.
  • Potential impact and severity assessment.
  • Any suggested fixes or mitigations (optional).

Response Timeline

  • Acknowledgment: Within 48 hours of receiving your report.
  • Initial Assessment: Within 7 days.
  • Resolution: Depending on severity and complexity, typically within 30 days.

Disclosure Policy

  • We will work with you to understand and resolve the issue promptly.
  • Once a fix is available, we will coordinate disclosure timing with you.
  • Credit will be given to reporters (unless anonymity is preferred).

Security Best Practices

When using this library:

  • Keep dependencies up to date.
  • Review generated code before deploying to production.
  • Validate timer durations and serialized snapshots before use.

Dependencies

This project uses Dependabot to monitor and update dependencies for security vulnerabilities. Security updates are prioritized and applied promptly.

There aren't any published security advisories