Skip to content

Security: locke69321/pullvault

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report security issues using GitHub's private vulnerability reporting: Security tab → AdvisoriesReport a vulnerability.

If you cannot use that workflow, contact the maintainers by another private channel (please avoid public issues for security reports).

Scope

In scope:

  • PullVault source code and official release artifacts.

Out of scope:

  • Third-party dependencies (please report to their maintainers first).
  • Self-hosted deployments with local modifications.

Supported Versions

Only the default branch (main) and the latest release (when available) receive security fixes.

Disclosure

We practice coordinated disclosure. Please allow a reasonable time for investigation and fixes before any public disclosure.

There aren’t any published security advisories