Skip to content

Security: vana-com/personal-server-ts

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability, please report it responsibly.

Do NOT open a public issue.

How to Report

  1. Email dev@vana.com with the subject line: [SECURITY] personal-server-ts — <brief description>
  2. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

Action Timeframe
Acknowledgement Within 48 hours
Initial assessment Within 5 days
Fix or mitigation Within 90 days
Public disclosure After fix ships

Scope

This policy covers the personal-server-ts repository including all workspace packages (core, server, cli).

Recognition

We appreciate responsible disclosure and will credit reporters in the release notes (unless anonymity is requested).

Supported Versions

Version Supported
latest Yes

There aren’t any published security advisories