Skip to content

Security: tetframework/tet

SECURITY.md

Security Policy

Supported Versions

Security updates are provided for the latest released version of tetframework/tet.

Older versions may receive fixes at the maintainers’ discretion, depending on severity and feasibility.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Report vulnerabilities privately using GitHub Security Advisories:

https://github.com/tetframework/tet/security/advisories/new

Include as much detail as possible:

  • affected version or commit
  • vulnerability description
  • reproduction steps or proof of concept
  • expected impact
  • suggested mitigation, if known

Response Process

After receiving a report, the maintainers will aim to:

  1. acknowledge receipt;
  2. assess severity and affected versions;
  3. prepare and review a fix;
  4. publish a patched release;
  5. disclose the vulnerability when appropriate.

Reports made in good faith will be treated respectfully.

Disclosure

Please allow the maintainers reasonable time to investigate and fix the issue before public disclosure.

Coordinated disclosure is preferred.

There aren't any published security advisories