Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Report privately through GitHub Security Advisories — open the affected repository, go to the Security tab, and choose Report a vulnerability. This creates a private advisory visible only to you and the maintainers.
If the repository has advisories disabled, or you would rather not use GitHub, email alanis@dragondev.cc.
Please include:
- The repository and version, commit, or release tag affected.
- A description of the issue and its impact.
- Steps to reproduce, ideally a minimal proof of concept.
- Any suggested remediation, if you have one.
- Acknowledgement within 3 working days.
- An initial assessment, including whether we accept the report and a rough severity, within 10 working days.
- Progress updates at least every 14 days while we work on a fix.
- Credit in the advisory and release notes, unless you ask otherwise.
We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We aim to publish an advisory within 90 days of the report, sooner where the fix is straightforward.
This policy covers the source code in DragonSecurity repositories. Findings against third-party dependencies should go to that project's maintainers — though we appreciate a heads-up so we can pin or patch.
Out of scope: reports generated solely by automated scanners with no demonstrated impact, social engineering, physical attacks, and denial of service through sheer volume of traffic.
We will not pursue or support legal action against anyone who makes a good-faith effort to comply with this policy. If a third party brings action against you for research conducted in line with it, we will make that good faith known.