Skip to content

Security: koo-projects/faved

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release receives security updates. Please upgrade to the latest version before reporting an issue.

Reporting a Vulnerability

Please report security issues privately — do not open a public issue, pull request, or discussion.

Please include what you can:

  • the affected version or commit;
  • the component/endpoint involved and a description of the issue;
  • reproduction steps or a proof of concept;
  • your assessment of the impact.

What to Expect

  • Acknowledgement within 2 business days.
  • We confirm the issue, assess severity, and keep you updated on progress.
  • Fixes are shipped in a new release and disclosed via a GitHub Security Advisory, with a CVE requested where warranted.
  • We credit reporters in the advisory by default — tell us if you'd prefer to remain anonymous.

Coordinated Disclosure

Please give us reasonable time to release a fix before disclosing publicly. We aim to resolve and publish an advisory within 90 days and will coordinate the timing with you.

Scope

This policy covers the Faved application code in this repository. Vulnerabilities in third-party dependencies should be reported upstream.

There aren't any published security advisories