Skip to content

Security: Aeluin-Technologies/Galadril

SECURITY.md

Security Policy

Security Reporting Process

If you discover a security vulnerability or a critical crash within Galadril, please do not open a public GitHub issue. Instead, please report it privately to ensure we can fix it before it becomes public knowledge.

The preferred reporting channel is to open a GitHub Security Advisory. This allows you to safely disclose the details, and allows us to collaborate on a fix in a private fork.

Alternatively, you can reach out directly via email at: aeluin@gravitalia.com

Thank you for helping keep Galadril secure during its early stages!


Supported Versions

As Galadril is currently in active early development, security fixes are only provided for the latest state of the repository (main branch).

Version Supported
main ✅ Yes
< main ❌ No

Disclosure and Fix Process

  1. Acknowledgment: We will acknowledge receipt of your vulnerability report within 2 business days.
  2. Fix Development: A fix will be developed privately. If reported via GitHub Advisories, you can be added to the private space to collaborate or review the patch.
  3. Release & CVE: Once the fix is ready, it will be merged into the main branch. A public Security Advisory will be published, and a CVE will be requested if applicable to notify the community.

There aren't any published security advisories