Skip to content

Security: achille010/dev-tips

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of dev-tips are currently receiving security updates:

Version Supported
latest ✅ Yes
older ❌ No

This project follows a rolling release model — only the latest version on main is actively maintained.


Reporting a Vulnerability

If you discover a security vulnerability in this repository, please do not open a public GitHub issue.

Instead, report it responsibly using one of the methods below:

📧 Private Disclosure

  • GitHub Security Advisories: Submit a private advisory
  • Email: If you prefer email, reach out directly to the repository owner via their GitHub profile contact.

What to Include

When reporting, please provide as much of the following as possible:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact or attack scenario
  • Any suggested mitigations or fixes (optional but appreciated)

Response Timeline

Stage Timeframe
Acknowledgement of report Within 48 hours
Initial triage & assessment Within 5 days
Fix or mitigation published Within 30 days (depending on severity)

Scope

This repository primarily contains developer tips, guides, and reference material. Security concerns may include but are not limited to:

  • Scripts or code samples with unsafe practices (e.g., command injection, insecure defaults)
  • Dependency vulnerabilities in any tooling used in this repo
  • Sensitive data accidentally committed (tokens, credentials, keys)

Out of Scope

The following are not considered security vulnerabilities for this project:

  • Typos or inaccurate technical content (open a regular issue instead)
  • Feature requests
  • Issues with third-party tools or services referenced in tips

Disclosure Policy

This project follows responsible disclosure. Once a vulnerability is confirmed and a fix is available, a security advisory will be published via GitHub Security Advisories.

We kindly ask reporters to refrain from public disclosure until a fix has been released.


Credits

We appreciate the security community's efforts in keeping open-source projects safe. Verified reporters may be acknowledged in the release notes (with permission).


Last updated: March 2026

There aren’t any published security advisories