Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Security: 1SHAMAY1/TimeEngine

Security

.github/SECURITY.md

Security Policy

Supported Versions

We actively provide security patches and bug fixes for the latest development branch and released versions:

Version Supported
main (Latest)
>= 0.1.0
< 0.1.0

Reporting a Vulnerability

We take the security and integrity of TimeEngine seriously. If you discover a security vulnerability, please follow responsible disclosure practices:

  1. Do NOT disclose the vulnerability publicly (do not open public issues, discussions, or pull requests disclosing exploit details).
  2. Report via GitHub Private Security Advisories (Preferred):
    • Navigate to the Security Advisories tab on GitHub.
    • Click "Report a vulnerability" to draft a private advisory directly with maintainers.
  3. Report via Email:
    • Alternatively, email the lead maintainer directly at [email protected] with the subject [TimeEngine Security Vulnerability].
  4. Include Detailed Information:
    • Provide a clear description of the vulnerability.
    • Include reproduction steps, proof-of-concept code, affected components/platforms, and potential impact.

Response Timeline

  • Initial Response: We will acknowledge receipt of your vulnerability report within 48 hours.
  • Assessment & Triage: Maintainers will confirm the vulnerability and determine its severity and scope within 5 business days.
  • Fix & Public Disclosure: A patch will be prepared in a private fork/security advisory and released alongside a security advisory disclosure once verified.

There aren't any published security advisories