Skip to content

Security: VocaHQ/.github

SECURITY.md

Security policy

This is the default security policy for VocaHQ repositories that do not have their own SECURITY.md. A repository's own policy takes precedence.

Supported versions

Security fixes normally target the current release and the default branch of each project. Check that project's README and releases for its current version. Older releases may not receive a fix.

Report a vulnerability

Please do not open a public issue, discussion, or pull request with details of an unpatched vulnerability. On the affected repository, open Security → Advisories → Report a vulnerability to send a private report. If that option is unavailable, email hello@vocahq.com with "Security report" and the affected repository in the subject.

Include the affected version or commit, impact, and steps to reproduce. Remove real credentials, recordings, transcripts, and private gateway addresses from logs and examples. We will assess the report, coordinate a fix and disclosure with you, and publish an advisory when appropriate.

There aren't any published security advisories