Skip to content

Security: stark256-spec/UltimateHealth

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of UltimateHealth are currently supported with security updates:

Version Supported
main βœ… Yes

Contact Details

To report a security vulnerability in UltimateHealth, please reach out via:

Please do not open a public GitHub issue for security vulnerabilities.

What to Include in Your Report

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Affected versions or components
  • Potential impact assessment
  • Any suggested fix (optional but appreciated)

Expected Response Time

Action Timeframe
Acknowledgement of report Within 48 hours
Status update Within 7 days
Patch / fix release Within 30 days

Responsible Disclosure Policy

We follow a responsible disclosure policy:

  • Please report vulnerabilities privately before any public disclosure
  • We request an embargo period of 30 days to investigate and patch the issue
  • After a fix is released, you are welcome to publish your findings
  • We will credit reporters in the patch notes unless anonymity is requested
  • We deeply appreciate the efforts of security researchers πŸ™

References

There aren't any published security advisories