Skip to content

Security: 4TUResearchData/djehuty

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in djehuty, please report it privately by emailing djehuty@4tu.nl.

Please do not open a public issue for security vulnerabilities.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Affected version(s)
  • Potential impact, if known

What to expect

  • Acknowledgment within 48 hours of your report.
  • A follow-up with our assessment and an estimated timeline for a fix within 7 business days.
  • Credit in the advisory, unless you prefer to remain anonymous.

Supported Versions

Version Supported
Latest Yes

Disclosure Policy

We follow coordinated vulnerability disclosure. After a fix is available, we will:

  1. Release a patched version.
  2. Publish a GitHub Security Advisory with details and remediation steps.
  3. Request a CVE identifier when appropriate.

We aim to resolve confirmed vulnerabilities within 90 days of the initial report.

There aren’t any published security advisories