Skip to content

Security: naveenkumarbaskaran/TokenShield

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

How to Report

  1. GitHub Security Advisory (preferred): Go to the Security tab of this repository and click "Report a vulnerability" to open a private advisory.

  2. Email: Send details to naveenkb142@gmail.com with the subject line [SECURITY] <repo-name> — <short description>.

What to Include

Field Details
Affected component File path, function, or endpoint
Description What the vulnerability is and how it can be exploited
Reproduction steps Minimal steps to trigger the issue
Impact assessment What an attacker could achieve
Suggested fix Optional, but appreciated

Response Timeline

Stage SLA
Acknowledgement 48 hours
Initial assessment 5 business days
Fix for critical issues 30 days

Scope

This policy applies to the latest version on the default branch. Vulnerabilities in outdated or unsupported versions may still be reviewed at maintainer discretion.

Disclosure

We follow coordinated disclosure — please allow us reasonable time to address the issue before making it public.


Thank you for helping keep this project and its users safe.

There aren't any published security advisories