Skip to content

Security: Ev3lynx727/ghostclaw

Security

SECURITY.md

Security Policy

This document describes how to report security vulnerabilities in Ghostclaw and our policy for handling them.

Supported Versions

We currently provide security updates for the following versions of Ghostclaw:

Version Supported
0.2.x
< 0.2.0

Reporting a Vulnerability

Do NOT open a public issue for security-related reports.

We prioritize the privacy of our maintainers and reporters. To report a security vulnerability, please use GitHub's Private Vulnerability Reporting feature:

  1. Navigate to the Security tab of this repository.
  2. Select Advisories from the left-hand sidebar.
  3. Click Report a vulnerability to open a private advisory.

Using this method ensures the report remains confidential and allows us to collaborate on a fix securely.

Disclosure Policy

When a vulnerability is reported through a private advisory:

  1. We will acknowledge the report within 48 hours.
  2. We will confirm the vulnerability and determine its severity.
  3. We will work on a fix in a private fork.
  4. Once fixed, we will publish the security advisory and release a new version of Ghostclaw.

Note

This policy helps protect the project and its users from premature disclosure. Thank you for your cooperation in keeping Ghostclaw secure!

There aren't any published security advisories