This policy applies to every public repository in the drumandbytes organization
that does not ship its own SECURITY.md.
Do not open a public issue for security problems.
Preferred: use GitHub's private vulnerability reporting — the "Report a vulnerability" button under the Security tab of the affected repository.
Alternative: email contact@drumandbytes.com with:
- the repository and version / commit affected,
- a description of the issue and its impact,
- steps to reproduce or a proof of concept,
- any suggested fix.
- Acknowledgement within 5 working days.
- An initial assessment (severity, affected versions) within 10 working days.
- Fixes are prioritised by severity. You will be kept updated on progress and told when a fix ships.
- Credit in the release notes if you want it — let us know how to attribute you.
These are hobby and homelab projects maintained by one person. There is no bug bounty. Reports about dependencies should generally go upstream first; flag them here only if this org's code uses the dependency in an unusually risky way.