Skip to content

Security: bromso/metapowers

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest Yes

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do not open a public GitHub issue
  2. Use GitHub Security Advisories to report the vulnerability privately
  3. Alternatively, email security concerns to the maintainers

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 1 week
  • Fix timeline: depends on severity, typically within 30 days

Security Best Practices

When contributing, please:

  • Never commit secrets, tokens, or credentials
  • Use environment variables for sensitive configuration
  • Follow the principle of least privilege in code
  • Report any suspicious dependencies

There aren't any published security advisories