Skip to content

Security: SQLoot/.github

SECURITY.md

Security Policy

Reporting a Vulnerability

Please report security vulnerabilities privately.

  1. Do not open a public issue.
  2. Use GitHub Private Vulnerability Reporting in the affected repository (Security tab).
  3. If needed, contact us at security@sqloot.dev.

Please include:

  • Affected repository/package and version/commit
  • Reproduction steps or PoC
  • Impact assessment
  • Suggested mitigation (optional)

Response Targets

  • Acknowledgement: within 48 hours
  • Initial triage: within 7 days
  • Fix timeline:
    • Critical: as soon as possible
    • High: target within 30 days
    • Medium: target within 90 days

Scope

This policy applies to all repositories under the SQLoot organization.

Supported Versions

Version line Supported
Current main/default branch
Older versions

Contributor Security Requirements

  • Never commit secrets or credentials
  • Minimize sensitive logging
  • Keep dependencies updated
  • Use least-privilege tokens and permissions
  • Enable 2FA on your GitHub account

Coordinated Disclosure

We appreciate responsible disclosure and can credit reporters in release notes, unless anonymity is requested.

There aren’t any published security advisories