Skip to content

Security: KooshaPari/DataKit

SECURITY.md

Security Policy

Reporting

Do not open public issues for security findings. Instead:

Scope

  • Vulnerabilities in this repo's code, dependencies, or CI
  • Credential leaks
  • Supply-chain concerns (typosquatting, compromised deps)

Response

  • Acknowledgment within 48h
  • Triage + severity call within 7d
  • Fix timeline per severity (CRITICAL: 7d, HIGH: 30d, MEDIUM/LOW: next release cycle)

Disclosure

Coordinated. We'll publish an advisory once a fix is available or after 90d if unfixed.

There aren’t any published security advisories