Skip to content

Security: IntergatedCircuits/bitfilled

SECURITY.md

Vulnerability Disclosure Policy

Report a vulnerability

If you believe you have found a security vulnerability in this repository, please report it to us through coordinated disclosure.

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Please include as much of the information listed below as you can to help us better understand and resolve the issue:

  • The product(s) or asset(s) where you discovered the vulnerabilities
  • The type of issue (e.g., buffer overflow, SQL injection, or cross-site scripting)
  • Full paths of source file(s) related to the manifestation of the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration, hardware or software platform required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit the issue

Our commitments

Our vulnerability disclosure policy is designed to keep our products secure after release.

After receiving your report, we will:

  1. Confirm its reception within 5 days
  2. Update you with our progress every 2 weeks
  3. Aim to resolve the reported issues within 90 days

Should we need more time to resolve your findings, we may ask you to avoid disclosing them until a solution is in place.

If you wish, we can acknowledge you after the issue is resolved.

We the project maintainers will not pursue legal action when reporting vulnerabilities in accordance with the policy.

Your commitments

Please respect all applicable regulations and always remain responsible!

You are a good person and we appreciate you.

There aren't any published security advisories