| 1 | # Security policy |
| 2 | |
| 3 | ## Supported versions |
| 4 | |
| 5 | Security fixes target the latest published stable Codewhale release. Please |
| 6 | upgrade before reproducing a report when possible. |
| 7 | |
| 8 | | Version | Security fixes | |
| 9 | | --- | --- | |
| 10 | | Latest published stable release | Supported | |
| 11 | | Earlier releases | Upgrade to the latest stable release | |
| 12 | | Unreleased branches and development builds | Best effort; no release support commitment | |
| 13 | |
| 14 | ## Report a vulnerability privately |
| 15 | |
| 16 | Use [GitHub's private vulnerability report form](https://github.com/codewhale-hq/Codewhale/security/advisories/new). |
| 17 | Private vulnerability reporting is enabled for this repository. GitHub sends |
| 18 | the report to repository maintainers through a private security advisory. |
| 19 | Do not open a public issue or pull request containing an unpatched |
| 20 | vulnerability or exploit details. |
| 21 | |
| 22 | Include the affected version or commit, operating system, a minimal |
| 23 | reproduction, expected and observed behavior, and the security impact. |
| 24 | Remove credentials, tokens, provider keys, personal data, and unrelated |
| 25 | repository contents. If a credential was exposed, rotate it through its |
| 26 | provider before sharing a redacted reproduction. |
| 27 | |
| 28 | ## What to expect |
| 29 | |
| 30 | Maintainers review reports and discuss reproduction, impact, and remediation |
| 31 | in the private advisory. Response and fix times depend on severity and |
| 32 | available capacity; there is no guaranteed response deadline. Please keep |
| 33 | exploit details private while a fix and disclosure timing are discussed. |
| 34 | When a fix is ready, maintainers use the advisory to coordinate publication |
| 35 | and affected versions. Reports that are ordinary bugs may be redirected to |
| 36 | the public issue tracker after sensitive details are removed. |
| 37 |