Skip to content

Security: f00-sh/f00

SECURITY.md

Security Policy

Supported versions

Security fixes target the latest released version on the default branch (main). Older major versions receive fixes only when explicitly maintained.

Reporting a vulnerability

Do not open a public GitHub issue for security problems.

Email william@theesfeld.net with:

  1. A short description of the issue
  2. Steps to reproduce or a proof of concept
  3. Affected version or commit
  4. Impact assessment if known

You will receive an acknowledgment when the report is received. Please allow reasonable time for investigation before any public disclosure.

Preferred disclosure

  • Private report first
  • Coordinated public disclosure after a fix or mitigation is available
  • Credit for the reporter on request

Non-security bugs

Use the repository issue tracker for ordinary bugs and feature requests.

There aren't any published security advisories