Skip to content

Security: boostsecurityio/smokedmeat

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue in SmokedMeat, please report it privately using GitHub's Security Advisory feature:

  1. Go to the Security tab of this repository
  2. Click "Report a vulnerability"
  3. Fill out the private security advisory form

Please do not report security vulnerabilities through public GitHub issues.

What to Include

When reporting a vulnerability, please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • We will acknowledge receipt within 48 hours
  • We will provide an initial assessment within 7 days
  • We will work with you to understand and resolve the issue

Scope

This security policy applies to the SmokedMeat framework itself. For vulnerabilities in CI/CD pipelines discovered using SmokedMeat, please report those to the respective platform or organization owners.

There aren't any published security advisories