Skip to content

Security: Renozoic-Foundry/forge-public

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in FORGE, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please email support@renozoic.com or use GitHub's private vulnerability reporting feature:

  1. Go to the repository's Security tab
  2. Click Report a vulnerability
  3. Provide details of the vulnerability

Response Timeline

  • Acknowledgment: Within 48 hours of report
  • Initial assessment: Within 7 days
  • Fix or mitigation: Depends on severity, typically within 30 days

Scope

This policy covers the FORGE framework template and its distribution tooling. It does not cover consumer projects bootstrapped from the template — those are maintained independently by their respective owners.

Supported Versions

Only the latest version on the main branch is actively supported with security fixes.

There aren't any published security advisories