Skip to content

Security: Scetrov/FrontierSharp

SECURITY.md

Security policy

Supported versions

Maintainers have not published a supported-version matrix. Before relying on this policy for a particular release series, confirm the supported version with the maintainers. The latest release is the appropriate starting point for a security report.

Reporting a vulnerability

Please do not report security vulnerabilities in public issues. Use this repository's private vulnerability reporting channel.

Include affected versions, reproduction steps or proof of concept, impact, and any proposed mitigation.

If the report concerns an exposed secret, revoke or rotate it immediately and state that rotation in the private report without including the secret value.

What to expect

These are targets, not service-level guarantees:

  • acknowledge a private report within 7 calendar days;
  • provide a status update at least every 14 calendar days while triage or remediation is active; and
  • coordinate public disclosure within 90 calendar days of report receipt, subject to reporter coordination and remediation needs.

Maintainers assess impact and affected versions, coordinate a fix, and provide updates through the private report. Please allow time for a fix before public disclosure.

There aren't any published security advisories