Skip to content

Security: telagod/Kooix

Security

SECURITY.md

Security Policy

Supported Versions

Kooix is currently in MVP stage. Security fixes are applied on a best-effort basis to the latest main branch.

Version Supported
main
Others

Reporting a Vulnerability

Please do not open public issues for unpatched vulnerabilities.

Instead, report privately by contacting the maintainer via GitHub security advisory flow (preferred):

  1. Open the repository on GitHub.
  2. Go to SecurityAdvisories.
  3. Click Report a vulnerability.
  4. Include impact, reproduction steps, affected files/paths, and suggested remediation if available.

If advisory flow is unavailable, open a private communication channel with the maintainer and include the same information.

What to Include

  • Vulnerability type and impact
  • Reproduction steps / PoC
  • Affected commit/version
  • Suggested fix or mitigation
  • Any known exploit preconditions

Response Targets (Best Effort)

  • Initial triage response: within 72 hours
  • Confirmation and severity assessment: within 7 days
  • Patch target: as soon as practical based on risk and complexity

Disclosure Policy

  • We follow coordinated disclosure.
  • Please allow time for validation and patching before public disclosure.
  • Once fixed, we may publish a summary and remediation notes.

There aren’t any published security advisories