Skip to content

Security: zixcel/devino

SECURITY.md

Security policy

Reporting a vulnerability

Use this repository's Security tab and Report a vulnerability to submit a private report to maintainers. Do not open a public issue or pull request containing exploit details, credentials, customer data, or personal information. If private reporting is unavailable, use GitHub's private security-support channel and request a private reporting route before disclosing details.

Include affected versions, a minimal synthetic reproduction, expected and observed behavior, and impact. Remove real secrets and identifying data. Maintainers assess the report and coordinate a correction and disclosure. No response-time guarantee, bounty, or support contract is implied.

Supported versions

The current main branch is maintained during development. Released-version support is stated in release notes; older releases are not implicitly supported. Do not infer runtime safety from a source scan or a passing CI policy check. Dependencies, deployments, history, and application-specific authorization require their own checks.

There aren't any published security advisories