Skip to content

Security: diese-tech/sal-site

SECURITY.md

Security Policy

Reporting a vulnerability

Report security vulnerabilities privately through GitHub Private Vulnerability Reporting. Do not open a public issue or disclose the vulnerability publicly before a fix is available.

Include the affected route or component, reproduction steps, impact, and any suggested mitigation. Remove credentials, personal data, and production league data from screenshots or logs.

The maintainer targets acknowledgement within three business days. Remediation timing depends on severity, reproducibility, and deployment risk; confirmed reports will receive status updates through the private advisory.

There aren't any published security advisories