Skip to content

Security: Magenta-Mause/.github

Security

SECURITY.md

Security Policy

The Magenta-Mause team takes the security of Cosy seriously. Thank you for helping keep Cosy and its users safe.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, report it through GitHub Private Vulnerability Reporting (Security Advisories): open a private report via the "Security" tab → "Report a vulnerability" on the affected repository. This keeps the report confidential and lets us collaborate on a fix privately.

If the affected repository has no "Report a vulnerability" option, file the advisory against Cosy-Backend instead and say which repository and version it actually concerns.

Please include as much of the following as you can:

  • The affected component/repository and version or commit.
  • A description of the vulnerability and its potential impact.
  • Steps to reproduce or a proof of concept.
  • Any suggested mitigation, if known.

What to Expect

  • We will acknowledge your report as soon as we are able.
  • We will investigate and keep you informed of our progress.
  • We ask that you give us a reasonable amount of time to release a fix before any public disclosure (coordinated disclosure).

Supported Versions

Cosy is under active development. Security fixes are applied to the latest release on the default branch. We generally do not backport fixes to older releases; please upgrade to the most recent version to receive security updates.

There aren't any published security advisories