Skip to content

Security: cvsouth/go-package-analyzer

SECURITY.md

Security Policy

Supported Versions

We currently support the following versions with security updates:

Version Supported
latest

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security vulnerability in this project, please report it responsibly.

How to Report

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by:

  1. Email: contact@colinsouth.com
  2. GitHub Security Advisories: Use GitHub's private vulnerability reporting feature by going to the Security tab of this repository and clicking "Report a vulnerability"

What to Include

When reporting a vulnerability, please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact of the vulnerability
  • Any suggested fixes or mitigation strategies
  • Your contact information for follow-up questions

Response Timeline

  • Acknowledgment: We will acknowledge receipt of your vulnerability report within 48 hours
  • Initial Assessment: We will provide an initial assessment within 5 business days
  • Resolution: We aim to resolve critical vulnerabilities within 30 days

Disclosure Policy

  • We follow responsible disclosure practices
  • We will work with you to understand and resolve the issue before any public disclosure
  • We will credit you for the discovery (unless you prefer to remain anonymous)
  • We may request that you keep the vulnerability confidential until we have a fix available

Security Best Practices

When using this tool:

  • Always use the latest version
  • Validate any configuration files before use
  • Be cautious when analyzing untrusted code repositories
  • Report any suspicious behavior

Contact

For security-related questions or concerns, please use the reporting methods outlined above.

Thank you for helping to keep our project and community safe!

There aren’t any published security advisories