Skip to content

Security: nsawill1405/SignalX

SECURITY.md

Security Policy

Supported Versions

SignalX follows a rolling support model focused on the latest release line.

Version Supported
0.1.x Yes
< 0.1.0 No

Reporting a Vulnerability

Please do not report security issues in public GitHub issues.

Use one of these private channels:

  1. Open a private GitHub vulnerability report: https://github.com/nsawill1405/SignalX/security/advisories/new
  2. If that page is unavailable, open a standard issue with no exploit details and request a private contact channel.

Include as much detail as possible:

  • Affected version(s)
  • Impact and attack scenario
  • Reproduction steps or proof of concept
  • Any suggested mitigation

Response Expectations

  • Initial acknowledgement: within 72 hours
  • Triage decision (severity/scope): within 7 days
  • Status updates: at least every 7 days until resolution

Disclosure Process

Please allow time for a fix before public disclosure. After a patch is available, coordinated disclosure is welcome and appreciated.

There aren’t any published security advisories