SystemsLabs promotes ethical security research and coordinated disclosures. If you find a security issue in any SystemsLabs project, kindly notify us privately for investigation and resolution.
| Version | Supported |
|---|---|
| latest | ✅ |
| < latest | ❌ |
Email: security@systemslabs.dev
Alternatively, use GitHub Private Security Advisories.
Please report vulnerabilities privately and include:
- Issue description
- Steps to reproduce the issue
- Affected project or module
- Potential impact, where applicable
Kindly refrain from any public announcements until a solution is found.
Don'ts:
- Publicly disclose vulnerabilities without coordination
- Engage in any form of social engineering
- Test your skills via denial-of-service attacks
- Access, modify, or exfiltrate data that is not yours
- Perform unauthorized access to systems or accounts
SystemsLabs aims to:
- Acknowledge reports according to the SLA below.
- Investigate the issue.
- Work on mitigations.
- Coordinate disclosure after the issue is resolved.
| Severity | Acknowledge | Patch Target |
|---|---|---|
| Critical | 24 hours | 7 days |
| High | 48 hours | 14 days |
| Medium | 5 days | 30 days |
| Low | 10 days | 90 days |
Coordination enables responsible disclosure. The issue can be publicly announced only after addressing it.
The policy applies to SystemsLabs repositories, documents, automation, and any project-related infrastructure.