Skip to content

Security: PerryLink/dsh-memento

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report vulnerabilities privately through GitHub's private vulnerability reporting:

  1. Open the Security tab of this repository.
  2. Click Report a vulnerability.

Do not open a public issue containing a working exploit or sensitive details.

Redact before submitting

Remove everything sensitive before you submit: tokens, API keys, credentials, request headers, private absolute paths, and any real user memory content. Logs, error messages, and reproduction steps must contain only the minimum needed to reproduce the issue.

What to include

  • Affected version(s)
  • A short description of the issue
  • Steps to reproduce (redacted)
  • Expected vs. observed behavior
  • Optional: a suggested fix

Response expectations

  • First acknowledgement within 7 days (usually much faster).
  • Status updates at least once every 14 days until resolution.
  • After confirmation, the fix is published as a patch release and announced in the changelog.

Disclosure & credit

  • Coordinated disclosure: the report stays private until a fix is released.
  • Reporters are credited (by name or handle, as they prefer) in the changelog and release notes unless they ask to remain anonymous.

There aren't any published security advisories