Skip to content

Security: devshieldhq/devshield-action

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x
< 1.0

Reporting a Vulnerability

The DevShield team takes security seriously.

If you discover a security vulnerability, please do not open a public GitHub issue.

Instead, report it privately.

Contact

Email:

devshieldhelpdesk@gmail.com

or

Open a confidential security advisory through GitHub.


Please Include

  • Description of the vulnerability
  • Steps to reproduce
  • Impact
  • Affected version
  • Proof of Concept (if available)
  • Suggested remediation (optional)

Response Timeline

Stage Target
Initial Response 48 hours
Investigation 5 business days
Security Fix As soon as possible
Public Disclosure After a patch is available

Scope

We appreciate reports involving:

  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Authentication Bypass
  • Authorization Issues
  • Path Traversal
  • SSRF
  • XSS
  • Prototype Pollution
  • Sensitive Data Exposure
  • Dependency Vulnerabilities
  • GitHub Action Security

Out of Scope

The following are generally not considered security vulnerabilities:

  • Typographical errors
  • Documentation issues
  • Feature requests
  • Rate limiting suggestions
  • Denial of Service requiring unrealistic resources
  • Social engineering attacks

Thank you for helping keep DevShield secure.

There aren't any published security advisories