Skip to content

Security: schivei/GenDI

SECURITY.md

Security Policy

Reporting a Vulnerability

The GenDI team takes security seriously. If you discover a security vulnerability, please do not open a public GitHub issue. Instead, follow the responsible disclosure process below.

How to Report

  1. Email: Send details to the maintainer at the email address listed on the GitHub profile.
  2. Subject line: Use the format [SECURITY] <brief description>.
  3. Include:
    • A description of the vulnerability and its potential impact.
    • Steps to reproduce (proof-of-concept code is helpful).
    • Any suggested mitigations or fixes.

What to Expect

  • Acknowledgement: Within 72 hours.
  • Assessment: Initial assessment within 7 days.
  • Fix and Disclosure: Patch released within 30 days of a confirmed vulnerability.

Scope

This policy applies to the GenDI NuGet package and the source code in this repository.

Out of Scope

  • Vulnerabilities in third-party dependencies (report those to their maintainers).
  • Issues already publicly disclosed before the report is submitted.

Thank you for helping keep GenDI and its users safe!

There aren't any published security advisories