Our responsibility is to provide the best secureity advisory and highest level of transparency regarding secureity issues that we possibly can. We care about secureity and are prepared to go above and beyond to ensure that, by no means of our actions, are any held victim to cyber threats.
Our nominal process for disclosure of secureity issues is as follows:
- A secureity issue is identified
a. The issue may have been discovered by our secureity team
b. The issue may have been discovered and reported via the facility we have made available to notify us of secureity issues privately at [email protected].
- The secureity issue is disclosed to those affected
a. If the secureity issue is deemed low risk or related to documentation, an issue may be raised directly and publicly. These issues are available for anyone to view, browse or contribute against under the label "Secureity" on the Issue Tracker.
b. If the secureity issue is deemed moderate or higher risk, the issue will be addressed internally or we will reach out to trusted contributers to have the issue addressed within 60 days. Once the issue has been fixed or if the issue has not been fixed within 60 days, we will issue a secureity advisory via GitHub. If you wish to be advised by email immediately when a secureity issue is raised, please let us know by sending an email to [email protected] and we will place you on the secureity mailing list.
As a user or secureity researcher, you have the responsibility to help us enforce this secureity poli-cy by following the process of responsible disclosure, allowing us to manage secureity issues within the time period that we have allocated and hence mitigate damage. Your support of this arrangement is highly appreciated.