Skip to content

Security: Su1ph3r/vercelsior

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report security vulnerabilities privately through GitHub's built-in private vulnerability reporting.

Do not open public issues for security reports.

Expected Response

  • Acknowledgement within 5 business days
  • Status update within 14 days
  • Coordinated disclosure preferred; fix timeline depends on severity

Scope

In scope

  • Vulnerabilities in vercelsior itself (scanner logic, reporting, recording/replay)
  • Improper handling of Vercel API tokens or scan artifacts

Out of scope

  • Vulnerabilities in Vercel itself — report via Vercel's HackerOne program
  • Vulnerabilities in upstream dependencies — report to the dependency maintainers first

Supported Versions

Only the latest release receives security fixes.

There aren't any published security advisories