Skip to content

Security: deployah-dev/deployah

SECURITY.md

Security policy

Supported versions

Security fixes are released for the latest stable version only. Upgrade to the newest release when a security update is published.

Reporting a vulnerability

Do not open a public GitHub issue or pull request for a security vulnerability.

Report privately through GitHub Security Advisories.

Include as much of the following as you can:

  • Description of the issue
  • Steps to reproduce, or a proof of concept
  • Affected versions (or git commit)
  • Potential impact
  • Any mitigations you already know

Response

We aim to acknowledge reports within 3 business days, and to provide an initial assessment within 14 days. Confirmed vulnerabilities are fixed as quickly as practical, then disclosed through a GitHub Security Advisory and a release. We credit reporters in the advisory unless you ask to stay anonymous.

Scope

This policy covers Deployah itself (the CLI and its repository). Vulnerabilities in upstream dependencies should normally be reported to those projects. If a dependency issue is widely distributed through Deployah and you are unsure where to report it, use the private advisory form above and we will help route it.

Advisories

Published advisories appear under Security advisories.

There aren't any published security advisories