Skip to content

Security: bold-minds/each

SECURITY.md

Security Policy

Supported Versions

Only the latest released minor version receives security patches.

Version Supported
latest
older

Reporting a Vulnerability

Do not open a public GitHub issue for security problems.

1. Report Privately

Report via GitHub Security Advisories. This creates a confidential channel between you and the maintainers.

If the Security Advisories flow is unavailable, email security@bold-minds.com.

2. What to Include

  • A description of the issue and its impact
  • Steps to reproduce or a proof-of-concept
  • The version affected
  • Your Go version and OS, if relevant
  • Any suggested mitigation

3. Response Timeline

  • Initial acknowledgement: within 48 hours
  • Triage + severity assessment: within 7 days
  • Resolution: varies based on complexity, typically within 30 days

You will be credited in the release notes unless you request otherwise.

4. Disclosure Process

  1. We acknowledge receipt of your vulnerability report
  2. We investigate and validate the vulnerability
  3. We develop and test a fix
  4. We coordinate disclosure timing with you
  5. We release a security update
  6. We publicly acknowledge your responsible disclosure (if desired)

Security Updates

Security updates will be:

  • Released as patch versions
  • Documented in CHANGELOG.md
  • Announced through GitHub releases
  • Tagged with security labels

Acknowledgments

We appreciate responsible disclosure and will acknowledge security researchers who help improve the security of this project.

There aren’t any published security advisories