Skip to content

Security: ieee-cs-bmsit/unipm

Security

SECURITY.md

Security Policy

Supported Versions

Use this section to tell people about which versions of your project are currently being supported with security updates.

Version Supported
1.0.x
< 1.0

Reporting a Vulnerability

We take the security of unipm seriously. If you believe you have found a security vulnerability in unipm, please report it to us as described below.

DO NOT report security vulnerabilities through public GitHub issues.

Instead, please send an email to [atul.k.m@ieee.org].

You should expect to receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

Information to Include

Please include as much of the following information as possible in your report:

  • The specific version of unipm affected.
  • Steps to reproduce the issue.
  • Any relevant configuration files or example code.
  • A description of the impact of the vulnerability.
  • Your name and affiliation (optional).

Our Response Process

  1. Acknowledgment: We will acknowledge receipt of your report within 24 hours.
  2. Assessment: We will investigate the issue and determine its severity and impact. We may contact you for further information.
  3. Fix: If a vulnerability is confirmed, we will work on a fix. We will keep you updated on our progress.
  4. Disclosure: Once a fix is available and released, we will publicly disclose the vulnerability (with your permission, crediting you for the discovery). We aim to provide a reasonable amount of time for users to upgrade before disclosing full details.

Security Best Practices for Contributors

  • Review the CONTRIBUTING.md guide.
  • Avoid committing secrets or sensitive information.
  • Use the provided safety features (e.g., input sanitization) when developing new features.
  • Run tests and security scans (once available) before submitting pull requests.

License

This security policy is part of the unipm project and is licensed under the MIT License.

There aren't any published security advisories