| Version | Supported |
|---|---|
| 1.3 | ✅ |
| < 1.3 | ❌ |
Please report security vulnerabilities via GitHub's private vulnerability reporting feature:
https://github.com/andrewtryder/repo-standards/security/advisories/new
Do not file a public issue for vulnerability reports. We will acknowledge receipt of your report and work with you to understand the scope and impact of the issue before any public disclosure.
- Acknowledgment: Within 5 business days of receiving your report.
- Resolution timeline: Within 10 business days of acknowledgment, we will provide a target date for a fix.
- Public disclosure: A fix will be published before any public disclosure.
This security policy covers the scripts, workflows, and configuration files maintained in this repository. It does not cover third-party tools (such as Black, ShellCheck, pre-commit, Hadolint, etc.) that this repository configures or recommends. Vulnerabilities in those tools should be reported to their respective maintainers.