Skip to content

Security: Novalabs-in/.github

Security

SECURITY.md

Security Policy πŸ›‘οΈ

We take the security of our repositories, products, and community seriously. If you believe you have found a security vulnerability in any of our projects, please report it to us using the procedure outlined below.


πŸ“… Supported Versions

We actively support and patch the latest major version of all production repositories. The following table highlights our support status:

Version Supported
Latest release (main) Active Security Support
Previous minor releases Best-effort updates
Major version -1 Critical security patches only
Older versions Unsupported

πŸ”’ Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

To report a vulnerability:

  1. Send an email to security@www.saitejabandaru.com.
  2. If possible, include:
    • The name of the affected repository.
    • A detailed description of the vulnerability and its potential impact.
    • Detailed step-by-step instructions or a Proof of Concept (PoC) script to reproduce the issue.
    • Any proposed remediation or fixes.

⏱️ Response and Disclosure Timeline

We aim to handle all security reports responsibly and promptly:

  • Triage: We will acknowledge receipt of your report within 24–48 hours and provide an initial assessment.
  • Fix: We will work on a fix as quickly as possible, typically within 7–14 days depending on complexity.
  • Disclosure: We coordinate the public disclosure of the vulnerability with the reporter, ensuring that users have had time to patch their installations.

πŸ•ŠοΈ Safe Harbor

We support security research conducted in good faith. If you follow this policy, we will:

  • Consider your research authorized and protect your identity (unless disclosure is legally required).
  • Work with you to understand and resolve the issue quickly.
  • Avoid initiating legal actions or law enforcement referrals against you.

Thank you for helping keep the Novalabs-in community secure! πŸš€

There aren't any published security advisories