Skip to content

Security: awareride/community

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

The AwareRide team takes security seriously. If you discover a security vulnerability in any AwareRide repository, please report it privately — do not open a public issue.

How to report:

We will acknowledge receipt within 48 hours and will work with you to:

  1. Confirm and assess the reported issue.
  2. Coordinate a fix and coordinated disclosure timeline.
  3. Credit you for the discovery (if you wish to be credited).

Scope

This policy applies to all public repositories under the AwareRide organization.

Out of Scope

  • Issues already reported in public GitHub issues or discussions.
  • General feature requests or non-security bug reports (please use GitHub Issues/Discussions for those).

Disclosure

We ask that you allow us a reasonable period (typically 90 days) to fix and release a patch before public disclosure.

Thank you for helping keep AwareRide and its community safe.

There aren't any published security advisories