Harrison Ward Technology takes security seriously. This policy applies to all public repositories in this organization.
Do not open a public issue for a security vulnerability.
Report it privately using either method:
- GitHub Security Advisory (preferred) — go to the Security tab of the affected repository and click "Report a vulnerability"
- Email — security@harrisonward.com
Please include:
- The repository and version or commit affected
- A description of the issue and its impact
- Steps to reproduce, or a proof of concept
- Any suggested fix, if you have one
| Stage | Timeline |
|---|---|
| We acknowledge your report | Within 2 business days |
| We confirm and assess severity | Within 5 business days |
| We ship a fix or share a mitigation plan | Within 30 days for high and critical issues |
| Public disclosure | After the fix ships, coordinated with you |
In scope
- Public repositories owned by this organization
- Published packages and releases we maintain
Out of scope
- Client systems and client-owned infrastructure. If you believe you found an issue affecting one of our clients, email us and we will route it appropriately
- Social engineering, physical security, and denial of service testing
- Findings from automated scanners without a demonstrated impact
Unless a repository states otherwise, we support the latest released version only. Older versions receive fixes for critical issues at our discretion.
We credit reporters in the advisory and release notes unless you ask us not to. We do not currently run a paid bounty program.
If you are an existing client with an active security incident, do not use this channel. Contact the help desk directly for immediate response.