Skip to content

Security: sevro/question

SECURITY.md

Report a security issue

The Question project welcomes security reports and is committed to providing prompt attention to security issues. Security issues should be reported privately via d.j.goddeau@gmail.com. Security issues should not be reported via the public Github Issue tracker.

Vulnerability coordination

Remediation of security vulnerabilities is prioritized. The project team coordinates remediation with third-party project stakeholders via Github Security Advisories. Third-party stakeholders may include the reporter of the issue, affected direct or indirect users of Question, and maintainers of upstream dependencies if applicable.

Security advisories

The project team is committed to transparency in the security issue disclosure process. We announce security issues via project Github Release notes.

Security Updates

Security updates will be published as non-breaking changes via semantic versioning.

There aren’t any published security advisories