Skip to content

Security: monodox/bruce

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x.x

Reporting a Vulnerability

We take security seriously. If you discover a security vulnerability, please report it responsibly.

How to Report

  1. Do not open a public GitHub issue for security vulnerabilities.
  2. Email us at security@monodox.com with details of the vulnerability.
  3. Include the following in your report:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 5 business days
  • Resolution: Depends on severity, typically within 30 days

What to Expect

  • We will acknowledge your report promptly.
  • We will investigate and validate the issue.
  • We will work on a fix and coordinate disclosure with you.
  • We will credit you in the release notes (unless you prefer to remain anonymous).

Security Best Practices

  • Keep dependencies up to date
  • Never commit secrets or credentials
  • Use environment variables for sensitive configuration
  • Follow the principle of least privilege
  • Report suspicious activity to security@monodox.com

There aren't any published security advisories