Skip to content

Security: 23seriy/nba-box

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. Do not open a public issue
  2. Email the maintainer or use GitHub's private vulnerability reporting
  3. Include steps to reproduce the issue
  4. Allow reasonable time for a fix before public disclosure

Scope

This project handles GitHub tokens and API keys via environment variables. Please report any issues related to:

  • Token or credential exposure
  • Unsafe handling of secrets
  • Dependency vulnerabilities

Response

We aim to acknowledge reports within 48 hours and provide a fix or mitigation within 7 days.

There aren't any published security advisories