Skip to content

Security: codeforstartups/runbit

Security

SECURITY.md

Security Policy

Supported versions

Version Supported
main (pre-1.0) Yes
unpublished packages Yes — report before publish

Pulse is early. Treat every release as potentially breaking until 1.0.

Reporting a vulnerability

Do not open a public issue for security vulnerabilities.

Email codeforstartups@gmail.com with:

  1. A description of the issue
  2. Steps to reproduce
  3. Impact assessment
  4. Any suggested fix (optional)

You should receive an acknowledgement within 72 hours.

We will:

  • Confirm the issue and severity
  • Work on a fix privately when needed
  • Credit you in the advisory if you want attribution

Scope

In scope:

  • The @pulse/* packages in this repository
  • The official website build in website/
  • CI / release pipelines that could leak secrets

Out of scope:

  • Third-party provider plugins not maintained here
  • Issues that require physical access or social engineering
  • Denial of service against public GitHub infrastructure

Disclosure

We prefer coordinated disclosure. Please give us a reasonable window to patch before public write-ups.

There aren't any published security advisories