Skip to content

Security: phoenixsec-dev/phoenix

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not open public GitHub issues for security vulnerabilities.

Instead, report privately with:

  • affected version/commit
  • reproduction steps or proof-of-concept
  • impact assessment
  • any suggested mitigation

Preferred contact: security@phoenixsec.dev
If email is unavailable, open a private advisory through GitHub Security Advisories.

Response Expectations

  • Initial acknowledgment target: within 72 hours
  • Triage and severity assessment: as quickly as possible
  • Coordinated disclosure after fix availability

Scope

In scope:

  • authentication/authorization bypasses
  • secret disclosure risks
  • cryptographic misuse
  • audit integrity issues
  • mTLS/certificate trust issues

Out of scope:

  • issues requiring local root/system compromise
  • purely theoretical findings without realistic impact
  • social engineering/phishing

There aren't any published security advisories