Skip to content

Security: okedeji/hybernate

Security

SECURITY.md

Security Policy

Supported Versions

We actively support the latest version of this project.

Version Supported
latest ✅ Yes
older ❌ No

If you are using an older version, we recommend upgrading to the latest release to receive security updates.


Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

Do not open a public GitHub issue.

Instead, report it privately using one of the following methods:

To create a private advisory:

  1. Go to the "Security" tab of this repository
  2. Click "Report a vulnerability"
  3. Fill in the details

What to Include

Please include as much of the following as possible:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if you have one)

Response Timeline

We aim to:

  • Acknowledge receipt within 48 hours
  • Provide an initial assessment within 5 days
  • Work on a fix and release a patch as soon as possible

Disclosure Policy

  • We follow responsible disclosure
  • Once the issue is fixed, we may:
    • Publish a security advisory
    • Credit the reporter (if desired)

Scope

This policy applies to:

  • Core codebase
  • APIs and interfaces
  • Deployment configurations

Out of scope:

  • Issues in third-party dependencies (should be reported upstream)

Security Best Practices

If you're deploying this project:

  • Keep dependencies up to date
  • Restrict access to your cluster and infrastructure
  • Follow Kubernetes security best practices
  • Do not expose internal services publicly without proper authentication

Contact

For any security-related concerns, please contact:

tobiokedeji@gmail.com

There aren't any published security advisories