Skip to content

Security: feralbureau/bedrock-api

Security

SECURITY.md

security policy

thank you for taking the time to report a security issue. this page explains how to report vulnerabilities privately and what to expect.

  1. reporting
  • preferred: use GitHub Security Advisories for this repository so reports stay private until fixed.
  • if you cannot use the security advisory flow, contact a repo maintainer directly (do not post exploit details publicly).
  1. what to include
  • short summary and impact (what an attacker can do)
  • steps to reproduce (minimal, precise)
  • proof-of-concept (if available) — include only what's needed to reproduce
  • affected versions and environment
  • suggested mitigation if you have one
  1. timeline & coordination
  • we follow coordinated disclosure: we will acknowledge receipt within 3 business days and aim to triage/fix within a reasonable timeframe.
  • we typically request up to 90 days to fix before public disclosure, but we will coordinate timing with you.
  1. handling sensitive data
  • do not share private keys, passwords, or user data when reporting. if you need to share sensitive artifacts, ask for a secure channel.
  1. acknowledgement
  • if you want credit we can add you to a CONTRIBUTORS / SECURITY_ACKS file — tell us how you want to be credited.
  1. after disclosure
  • once a fix is available we will publish a CVE or advisory (if applicable) and post remediation steps.

thank you

  • maintainers

There aren’t any published security advisories