Skip to content

Latest commit

 

History

History
46 lines (34 loc) · 1.36 KB

File metadata and controls

46 lines (34 loc) · 1.36 KB

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Constellation Hub, please report it responsibly:

  1. Do NOT open a public GitHub issue for security vulnerabilities
  2. Email: security@constellation-hub.dev (or use GitHub's private vulnerability reporting)
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact assessment
    • Any suggested remediation

Response Timeline

Action Timeline
Acknowledge receipt Within 48 hours
Initial assessment Within 5 business days
Status update Every 7 days until resolved
Fix available Depends on severity (critical: ASAP)

Supported Versions

Version Supported
1.x.x ✅ Active
< 1.0 ❌ Not supported

Security Measures

  • All dependencies are scanned for known vulnerabilities
  • Container images are scanned before release
  • Security advisories are published via GitHub Security Advisories
  • Critical updates are released as soon as fixes are available

Disclosure Policy

We follow coordinated disclosure:

  1. Work with reporter to understand and verify the issue
  2. Develop and test a fix
  3. Release the fix and publish an advisory
  4. Credit the reporter (unless they prefer anonymity)

Thank you for helping keep Constellation Hub secure!