Skip to content

Security: RomeoRaven/operator-stack

Security

SECURITY.md

Security Policy

Supported versions

Only the latest commit on each repository's default branch and explicitly published releases, when present, receive security fixes. Candidate, incubation, and unreleased branches are not supported releases.

Reporting a vulnerability

Please do not disclose a suspected vulnerability in a public issue.

Use the affected repository's Security → Report a vulnerability form when private vulnerability reporting is enabled. If that form is unavailable, open a RomeoRaven account-support issue containing no vulnerability details and request a private reporting route from the maintainer. Do not include the affected repository, vulnerability, proof of concept, credentials, tokens, private hostnames, or personal data in that public issue.

In the private report, include the affected repository and revision, impact, reproduction steps, and any suggested mitigation. Do not include unrelated credentials, tokens, private hostnames, or personal data.

You should receive an acknowledgement within seven days. Disclosure timing will be coordinated after the report is assessed and a fix path is known.

There aren't any published security advisories