Skip to content

Security: braedonsaunders/oneshot

Security

SECURITY.md

Security Policy

Supported Versions

Security fixes are applied to the latest code on main.

Reporting a Vulnerability

Please do not open a public issue for undisclosed vulnerabilities.

Use one of the following:

  1. Preferred: GitHub private vulnerability report
    https://github.com/braedonsaunders/oneshot/security/advisories/new
  2. Fallback: contact the repository maintainers directly on GitHub if the advisory form is unavailable.

What to Include

  • Affected version/commit
  • Reproduction steps or proof of concept
  • Impact assessment
  • Any proposed mitigation

Response Expectations

  • Initial acknowledgment target: within 72 hours
  • Triage and remediation timeline depends on severity and exploitability
  • Credit is provided unless you request anonymity

There aren’t any published security advisories