-
Notifications
You must be signed in to change notification settings - Fork 0
incident response
dannyward630 edited this page Jun 28, 2026
·
1 revision
Report vulnerabilities privately using the process in SECURITY.md. Do not open a public issue containing exploit details, credentials, personal data, or an unpublished vulnerable source snapshot.
- Acknowledge and restrict sensitive details.
- Reproduce with the smallest safe fixture.
- Assess affected versions, packages, data, and hosted metadata.
- Revoke exposed credentials and pause affected network paths when necessary.
- Patch with regression tests and run security, package, and full verification gates.
- Publish a GitHub security advisory and patched release when users need action.
- Document whether cached or exported personal data needs deletion or redaction.
- Review similar adapters and shared parser/network code.
High and critical findings block release. Dependency, CodeQL, and secret-scanning alerts should be resolved at the cause or explicitly documented as verified false positives.