Skip to content

Security: francescopace/peoplemesh

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the active development branch and recent supported releases. If unsure, report the issue and maintainers will confirm applicability.

Reporting a vulnerability

Please do not open public issues for suspected vulnerabilities.

Report privately via:

  • security@peoplemesh.org

Include:

  • affected component and version/commit
  • reproduction steps or proof of concept
  • impact assessment
  • suggested remediation (if available)

Response goals

  • Initial acknowledgement: within 3 business days
  • Triage and severity assessment: as soon as reproducible
  • Coordinated disclosure after fix availability

Scope reminders

Common high-priority areas include:

  • authentication/session handling
  • authorization and entitlement checks
  • maintenance endpoints and key handling
  • personal data leakage paths
  • dependency vulnerabilities

There aren't any published security advisories