Skip to content

Security: R7rainz/dotfiles

Security

SECURITY.md

πŸ” Security Policy

πŸ“Œ Supported Versions

Currently, only the latest release and the active main branch receive security updates. Older versions or deprecated scripts are not supported.

Version Supported
main βœ… Yes
v1.0.x βœ… Yes
< v1.0 ❌ No

🚨 Reporting a Vulnerability

Security is a priority for this project.

If you discover a vulnerability (for example: unsafe privilege escalation in install.sh, insecure defaults, or risky dependency handling), please do NOT report it publicly via Issues.

Instead, report it privately using one of the following:

πŸ”’ Preferred Method

  • GitHub Private Vulnerability Reporting

    • Go to the Security tab β†’ Advisories β†’ Report a vulnerability

πŸ“§ Alternative Method


⏱️ What to Expect

  • Acknowledgment: You will receive a response within 48–72 hours

  • Investigation: The issue will be reviewed and validated. If confirmed, a fix timeline will be planned.

  • Resolution: A patch will be released for supported versions. You may be credited for responsible disclosure (optional).


πŸ™ Thank you for helping keep this project secure!

There aren’t any published security advisories