Skip to content

Security: get-backbone/backbone-kit

Security

SECURITY.md

Security Policy

Reporting Security Vulnerabilities

If you discover a security vulnerability in Backbone Kit, please report it responsibly.

Do not open a public GitHub issue for security-related concerns.

Instead, report vulnerabilities by emailing:

security@eagledrive.tech

Please include:

  • A description of the vulnerability
  • Steps to reproduce (if applicable)
  • Affected module(s) and version(s)
  • Any potential impact or mitigation suggestions

We will acknowledge receipt and investigate promptly.


Supported Versions

Backbone Kit follows semantic versioning.

Only the latest released version is actively maintained for security updates. Older versions may not receive fixes.


Scope

This policy applies to:

  • Source code within the Backbone Kit repository
  • Published Backbone Kit artifacts

This policy does not apply to:

  • Forks of the repository
  • Downstream applications using Backbone Kit
  • The commercial Backbone Platform (covered under separate agreements)

Security Philosophy

Backbone Kit is designed with:

  • Fail-closed defaults
  • Explicit security boundaries
  • Zero-trust assumptions
  • Minimal implicit behaviour

Consumers are responsible for:

  • Correct configuration
  • Identity provider integration
  • Secure deployment practices

Thank you for helping keep Backbone Kit secure.

There aren't any published security advisories