Skip to content

Security: wowdev-org/.github

SECURITY.md

Security Policy

Supported versions

Only the latest stable minor release of an actively maintained component is eligible for security fixes unless that repository publishes a broader support table. Unreleased, pre-stable, archived, and abandoned practice deployments are unsupported. Before the first stable release, reports are still welcome but no supported-version commitment is implied.

Private reporting

Do not disclose a suspected vulnerability in an issue, pull request, Discussion, public chat, or shared reproduction repository.

Prefer GitHub Private Vulnerability Reporting in the affected repository: open its Security tab, choose Advisories, and select Report a vulnerability. If private reporting is unavailable or the affected repository is uncertain, email qatoolist+security@gmail.com.

Include, when safely available:

  • affected repository, package, version, and configuration;
  • impact and realistic attack or failure scenario;
  • reproduction steps or proof of concept;
  • prerequisites and environmental assumptions;
  • suggested mitigation;
  • whether anyone else has been notified;
  • your preferred attribution and disclosure coordination.

Remove unrelated credentials, personal data, and production records. Encrypt especially sensitive material only after agreeing on a channel.

Response and disclosure

The project targets acknowledgement within three business days and an initial validity assessment within seven business days when reasonably possible. Accepted reports receive a progress update at least every 14 days while active. These are good-faith targets, not contractual service levels.

The project and reporter coordinate remediation and publication. The default maximum coordinated disclosure window is 90 days, adjustable by agreement based on impact, fix complexity, downstream coordination, and active exploitation. The project may disclose earlier when users face material risk, a fix is broadly available, or details are already public.

Do not access data you do not own, degrade services, persist access, exfiltrate information, or expand testing beyond what is necessary to demonstrate the issue. Good-faith research that respects these limits will not be threatened merely for reporting. This policy does not authorize activity prohibited by law or third-party terms.

WowDev does not currently offer a bug bounty or promise payment. Recognition is coordinated with the reporter.

There aren't any published security advisories