Skip to content

Security: docolin-dev/docolin

Security

SECURITY.md

Security policy

Reporting a vulnerability

If you discover a security vulnerability in docolin, please email security@docolin.com.

The mailbox is hosted on Proton Mail, so:

  • Mail sent from another Proton Mail account is end-to-end encrypted automatically.
  • Mail sent from any other provider can be encrypted with PGP (request our public key in your first message), or sent via Proton's password-protected reply once we respond.

Please do not file public issues, discussions, or pull requests for security reports. Coordinated disclosure protects users while we ship a fix.

When you report, please include:

  • A description of the issue and its impact
  • Steps to reproduce, or a proof of concept
  • Affected versions, if known
  • Your name or handle for credit (optional)

What to expect

  • We aim to acknowledge new reports within 72 hours.
  • We will keep you updated as we triage, fix, and release.
  • Once a fix is released, we will publish an advisory and credit you (unless you prefer to stay anonymous).

Scope

This policy covers code in this repository and any official docolin-dev services. Third-party dependencies should be reported upstream, but feel free to CC us if a vulnerability has direct impact on docolin.

Status

docolin is pre-alpha. There are no supported releases yet. Security reports against main are still very welcome.

There aren't any published security advisories