Skip to content

Security: cvsz/zlttbots

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest major release line.

Version Supported
2.0.x
1.x.x
< 1.0

Reporting a Vulnerability

To report a suspected vulnerability, use one of the channels below:

  • Email: security@zeazdev.com
  • Backup channel: Open a private security advisory in GitHub for this repository.

Please include:

  1. A clear summary of the issue and affected component(s).
  2. Reproduction steps or proof-of-concept details.
  3. Potential impact and suggested mitigations (if available).
  4. Your preferred contact information for follow-up.

Response Process and SLA

  • Acknowledgement target: within 2 business days.
  • Initial triage target: within 5 business days.
  • Status updates: at least every 7 calendar days while remediation is in progress.
  • Resolution goal: critical issues are prioritized for the nearest patch release.

Disclosure Policy

  • Do not publicly disclose vulnerabilities before a fix is released.
  • Coordinated disclosure is preferred.
  • Reporters acting in good faith will be credited in release notes unless they request anonymity.

Scope Notes

This policy covers code and infrastructure definitions in this repository. Third-party dependencies and external integrations should also be reported if the repository usage introduces exploitable risk.

There aren't any published security advisories