Skip to content

Conversation

@DankerMu
Copy link

Summary

Add a minimal SECURITY.md so security researchers have a clear, private reporting path.

Changes

  • Add SECURITY.md with reporting channels and expected response timelines

Addresses #80


## Bug Bounty

We do not currently run a formal bug bounty program. Valid reports may still be acknowledged in release notes or the security advisory, at our discretion.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

any possible CVE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants