Skip to content

Security: barbatdev/gentle-ai

Security

SECURITY.md

Security Policy

Supported versions

Unless a repository provides its own security policy, only its current default branch is supported. Archived versions, old commits, and unpublished forks may not receive security updates.

A repository-level SECURITY.md overrides this organization default.

Report a vulnerability

Do not report security vulnerabilities through public issues, pull requests, discussions, or Discord.

Use GitHub's private vulnerability reporting in the affected repository:

  1. Open the repository's Security tab.
  2. Select Advisories.
  3. Select Report a vulnerability.
  4. Submit the report privately.

Include enough information for the maintainers to investigate:

  • The affected repository, version, release, or commit.
  • A clear description of the vulnerability and its potential impact.
  • Reproduction steps or a minimal proof of concept.
  • Relevant configuration, prerequisites, logs, or screenshots.
  • A suggested mitigation, if you have one.

Remove credentials, tokens, personal data, and unrelated sensitive information from all evidence.

Coordinated disclosure

Keep the vulnerability and its details private until the maintainers confirm that disclosure is safe. The maintainers may request additional evidence, validate the impact, prepare a fix, and coordinate publication through a GitHub Security Advisory.

Response and remediation times depend on the scope, impact, and maintainability of the affected project. This policy does not promise a fixed response-time SLA.

Regular bugs and support

Use the repository's normal issue workflow for bugs, documentation problems, feature requests, and support questions that do not expose a security vulnerability.

There aren't any published security advisories