| Version | Supported |
|---|---|
| latest | ✅ |
Please do not report security vulnerabilities through public GitHub issues.
If you discover a security issue in driftcheck, please report it privately:
- Email: yunare@gmail.com
- Subject:
[driftcheck] Security Vulnerability - Include:
- Description of the vulnerability
- Steps to reproduce (if applicable)
- Potential impact
- Any suggested fixes (optional)
I will acknowledge receipt within 48 hours and work with you to address the issue. Once fixed, I will publish a security advisory and add a CHANGELOG entry.
I aim to address critical security issues within 7 days of disclosure. High-severity issues affecting actively exploited vectors will be prioritized.
This policy applies to driftcheck (yunaremaia/driftcheck), including all CI workflow templates, utility scripts, and documentation served from this repository.
If you report a vulnerability in accordance with this policy, you will not be subject to legal action or retaliation for good-faith security research.