Skip to content

Security: Nebulazer123/tower-upgrade-advisor

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

How to Report

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Use GitHub private vulnerability reporting if enabled, or contact the maintainer through the repository owner profile
  3. Include detailed steps to reproduce the vulnerability
  4. Manual review required: a dedicated response-time policy has not been published yet

What to Include

  • Type of vulnerability
  • Full paths of affected source files
  • Location of the affected source code (tag/branch/commit or direct URL)
  • Step-by-step instructions to reproduce
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue

What to Expect

  • Acknowledgment timing depends on maintainer availability until a dedicated security contact is published
  • Regular updates on our progress
  • Credit in the security advisory (if desired)
  • Notification when the issue is fixed

Security Best Practices

When contributing to this project:

  • Never commit secrets, API keys, or credentials
  • Use environment variables for sensitive configuration
  • Follow secure coding practices
  • Report any security concerns immediately

Manual review: add a dedicated security email or enable GitHub private vulnerability reporting before accepting broad outside security reports.

There aren't any published security advisories