Skip to content

Security: EvezArt/evez-platform

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x

Reporting a Vulnerability

Please report security vulnerabilities to the maintainers privately. DO NOT open a public issue for security vulnerabilities.

  1. Email: Contact the maintainer
  2. Private GitHub Security Advisory: Use GitHub's private reporting
  3. Wait for acknowledgment (usually within 48 hours)
  4. Coordinate disclosure timeline

Scope

  • Authentication/authorization bypasses
  • Data exposure
  • Remote code execution
  • Injectable code
  • Dependency vulnerabilities

Out of Scope

  • Social engineering
  • Physical security
  • Denial of service (baseline)
  • Features marked experimental

There aren't any published security advisories