Skip to content

Security: FuroLabs/.github

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

  • Email furolabs@gmail.com with a clear, concise description, impact, and proof-of-concept (if available). Include affected repo/commit, logs or screenshots, and repro steps.
  • Do not open public GitHub issues for security reports.
  • For encryption, request our PGP key or include your key; we will respond with our fingerprint.

Triage Checklist (what to include)

  • Impact and severity as you see it
  • Affected repo, branch/commit, or release version
  • Reproduction steps and minimal proof-of-concept
  • Expected vs. actual result, plus any logs/screenshots

Response and Remediation Targets

  • Acknowledgment: within 2 business days
  • Initial assessment: within 5 business days
  • Status updates: at least weekly until resolution
  • Fix SLAs (targets): Critical 7 days; High 14 days; Medium 30 days; Low 60 days (business or calendar days depending on issue complexity)

Response Targets

  • Acknowledgment: within 2 business days.
  • Initial assessment: within 5 business days.
  • Status updates: at least weekly until resolution.

Disclosure

  • Coordinated disclosure by default; we will agree on a reasonable timeline with you.
  • We aim to publish advisories and fixes once a mitigation is available and users have had time to update.
  • We will request CVEs for qualifying issues and include acknowledgments when permitted.

Scope

  • In scope: code, configs, CI/CD workflows, secrets exposure, and infrastructure-as-code in this repository.
  • Out of scope: social engineering, physical attacks, spam or unsolicited automated traffic, and denial-of-service or load-testing against our infrastructure.
  • No brute-force attacks against accounts or rate-limit evasion.

Supported Versions

Version Status
main Actively supported
Older tags Best effort only; may require updating to main
Forks Out of scope unless explicitly covered by a separate agreement

Safe Harbor

  • If you make a good-faith effort to comply with this policy, avoid privacy violations, and do not degrade or disrupt services, we will consider your research authorized and will not pursue legal action.

Disclosure & credit

With your consent, Furo Labs may publicly credit you for responsibly reporting the issue. If you prefer anonymity, please state that in your report.

Contact

Email: furolabs@gmail.com

Thank you for helping us keep Furo Labs secure.

There aren’t any published security advisories