Skip to content

Security: Justagwas/MediaCrate

SECURITY.md

Security Policy

Thank you for helping keep Justagwas projects and their users secure.

Supported versions

For projects with published releases, security fixes are provided for the latest stable release line. For projects without numbered releases, the current default branch is the supported version. Archived repositories and superseded releases do not ordinarily receive security updates.

Reporting a vulnerability

Do not disclose a suspected vulnerability through a public issue, discussion, pull request, or social-media post.

Use GitHub's private vulnerability-reporting feature for the affected repository when it is available. Otherwise, email email@justagwas.com.

Include, where possible:

  • The affected project and version or commit.
  • A clear description of the issue and its potential impact.
  • Reproduction steps or a minimal proof of concept.
  • Relevant configuration and environmental details.
  • A suggested mitigation, if one is known.

Do not include credentials, access tokens, personal data, or unrelated private information.

Response and disclosure

  • An initial response is targeted within seven days.
  • Reports are assessed according to reproducibility, impact, and severity.
  • Additional information may be requested during investigation.
  • Public disclosure is coordinated after a correction or practical mitigation is available.
  • Reporter credit is provided when requested, unless anonymity is preferred.

Complex reports may require more time to investigate and resolve. Please allow a reasonable opportunity to address the issue before publishing details.

Ordinary defects

Crashes, incorrect output, compatibility problems, and other defects without a security impact should use the repository's normal issue tracker.

There aren't any published security advisories