Skip to content

Security: psamouelian/peoplemesh

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are provided for the active development branch and recent supported releases. If unsure, report the issue and maintainers will confirm applicability.

Reporting a vulnerability

Please do not open public issues for suspected vulnerabilities.

Report privately via:

  • security@peoplemesh.org

Include:

  • affected component and version/commit
  • reproduction steps or proof of concept
  • impact assessment
  • suggested remediation (if available)

Response goals

  • Initial acknowledgement: within 3 business days
  • Triage and severity assessment: as soon as reproducible
  • Coordinated disclosure after fix availability

Scope reminders

Common high-priority areas include:

  • authentication/session handling
  • authorization and entitlement checks
  • maintenance endpoints and key handling
  • personal data leakage paths
  • dependency vulnerabilities

There aren't any published security advisories