Skip to content

Security: DragonSecurity/dragonrun

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Report privately through GitHub Security Advisories — open the affected repository, go to the Security tab, and choose Report a vulnerability. This creates a private advisory visible only to you and the maintainers.

If the repository has advisories disabled, or you would rather not use GitHub, email alanis@dragondev.cc.

Please include:

  • The repository and version, commit, or release tag affected.
  • A description of the issue and its impact.
  • Steps to reproduce, ideally a minimal proof of concept.
  • Any suggested remediation, if you have one.

What to expect

  • Acknowledgement within 3 working days.
  • An initial assessment, including whether we accept the report and a rough severity, within 10 working days.
  • Progress updates at least every 14 days while we work on a fix.
  • Credit in the advisory and release notes, unless you ask otherwise.

We ask that you give us a reasonable opportunity to ship a fix before disclosing publicly. We aim to publish an advisory within 90 days of the report, sooner where the fix is straightforward.

Scope

This policy covers the source code in DragonSecurity repositories. Findings against third-party dependencies should go to that project's maintainers — though we appreciate a heads-up so we can pin or patch.

Out of scope: reports generated solely by automated scanners with no demonstrated impact, social engineering, physical attacks, and denial of service through sheer volume of traffic.

Safe harbour

We will not pursue or support legal action against anyone who makes a good-faith effort to comply with this policy. If a third party brings action against you for research conducted in line with it, we will make that good faith known.

There aren't any published security advisories