Skip to content

Security: GovTechSG/sgds-web-component

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Report suspected vulnerabilities to GovTech Vulnerability Disclosure Programme pag. Include:

  • A description of the issue and its potential impact
  • Steps to reproduce, or a proof of concept
  • Affected version(s) or commit

What to expect

  • Acknowledgement: we aim to acknowledge your report within 3 working days.
  • Updates: we will keep you informed as we investigate and work on a fix.
  • Disclosure: we follow coordinated disclosure and will agree timing with you before any public disclosure.

Supported versions

Note that only the latest release is supported, however our releases are backward compatible by SemVer versioning standards.

Coordinated disclosure

Where available, this project follows GovTech's coordinated vulnerability disclosure policy.

There aren't any published security advisories