Skip to content

Security: cboone/bopca

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via GitHub's private vulnerability reporting:

  1. Go to the repository's Security tab (in the top navigation bar, next to Issues/Pull Requests)
  2. Click "Report a vulnerability" in the left sidebar under Advisories
  3. Fill out the form with details

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 24 hours
  • Initial assessment: Within 48 hours
  • Resolution target: Depends on severity, but ASAP

What Qualifies as a Security Issue

  • Container escape vulnerabilities
  • Credential exposure risks
  • Command injection possibilities
  • Path traversal issues

Out of Scope

  • Issues in upstream dependencies (report to them directly)
  • Issues requiring physical access to the machine
  • Social engineering attacks

There aren’t any published security advisories