Skip to content

Security: dan-damit/TechToolbox

SECURITY.md

Security Policy

Supported Versions

The project currently supports the latest released version of TechToolbox and the corresponding actively maintained branch. If you are using an older release, we recommend upgrading to the latest version before reporting a vulnerability.

Reporting a Vulnerability

If you discover a security issue in this project, please report it privately and responsibly.

Please do not open a public GitHub issue for security vulnerabilities. The preferred workflow is to use GitHub Security Advisories for private vulnerability reporting.

To submit a report:

  • Go to the GitHub repository's Security tab.
  • Select "Report a vulnerability" to open a private advisory.
  • If private reporting is not available in the repository settings, contact the maintainers through the repository's security contact information and share the report privately.

When reporting, please include:

  • A clear description of the vulnerability
  • The affected component, version, and usage context
  • Steps to reproduce the issue
  • Any proof of concept or relevant logs
  • Your preferred contact information for follow-up

Response Expectations

We will review your report as quickly as possible and work with you to confirm and remediate the issue. We appreciate responsible disclosure and will do our best to acknowledge receipt and keep you informed as the investigation proceeds.

Coordinated Disclosure

We ask researchers and users to avoid public disclosure until a fix is available or an agreed remediation timeline has been established. We will work to address valid reports in a timely manner and credit reporters where appropriate.

Scope

This policy applies to security issues in the TechToolbox module, its shipped scripts, and related project assets. It does not cover third-party dependencies or services that are not maintained by this project.

There aren't any published security advisories