Skip to content

Security: SadPossum/GMA-Module-Notifications

SECURITY.md

Security Policy

Supported Versions

GMA Notifications is independently versioned. Security fixes are made on dev and included in the next tagged release. During the pre-1.0 period, only the latest tagged release and dev receive fixes.

Version Supported
dev Pre-release security fixes
v0.2.0 Yes
Older releases No

Report a Vulnerability

Use GitHub's private vulnerability reporting form. Do not open a public issue for an undisclosed vulnerability and do not include credentials, personal data, payment data, identity documents, or third-party confidential data in a report.

Include the affected commit or release, impact, reproducible steps or a minimal proof of concept, and any known mitigation. A composition issue may also be reported to GMA-Skeleton or the owning product repository; maintainers will route it privately.

We aim to acknowledge a complete report within three business days and provide an initial assessment within seven business days. These are response targets, not a contractual support SLA. Please coordinate public disclosure until a fix or mitigation is available.

There is currently no paid bug-bounty programme. Good-faith, non-destructive research against systems and data you own is welcome; denial of service, social engineering, persistence, and access to another person's data are out of scope.

There aren't any published security advisories