Skip to content

Security: rushhiii/klyvanta-docs

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
main (latest commit) Yes
Active release branch Yes
Older branches No

Reporting a Vulnerability

Please report security issues responsibly.

  1. Prefer GitHub private vulnerability reporting (Security tab -> Report a vulnerability) when available.
  2. Include affected area, impact, and clear reproduction steps.
  3. Include environment details, dependency versions, and any temporary mitigation.
  4. Do not disclose exploit details in public issues before a fix is shipped.

If private reporting is unavailable, open a public issue with minimal non-sensitive details and request a private follow-up channel.

Response Targets

  • Initial triage: within 3 business days
  • Status update: within 7 business days
  • Resolution timeline: depends on severity and complexity

Security Scope for This Project

Reports are especially valuable for:

  • docs rendering and MDX processing paths
  • API routes related to docs data and search
  • metadata, sitemap, and robots generation
  • dependency and build pipeline risks

Disclosure Process

After a fix is available, maintainers may publish a coordinated disclosure note that includes:

  • affected versions
  • fix commit or release reference
  • upgrade guidance

There aren't any published security advisories