Skip to content

Security: abhirajadhikary06/eventstack

Security

SECURITY.md

๐Ÿ” Security Policy

Thank you for helping keep EventStack secure! This document outlines the guidelines for reporting security issues and best practices.


๐Ÿ“… Supported Versions

We only provide security updates for the latest stable version of the project.

Version Supported
main โœ… Yes
older โŒ No

๐Ÿ“ข Reporting a Vulnerability

If you discover a security vulnerability, please do not create a public issue.

Instead, report it directly and confidentially to the project maintainer.

Please include the following information:

  • Description of the vulnerability
  • Steps to reproduce (if applicable)
  • The potential impact
  • Suggested remediation (if known)

โŒ› We will acknowledge your report within 72 hours and take appropriate action.


๐Ÿšซ Responsible Disclosure Guidelines

We ask that you:

  • Do not publicly disclose the issue until it has been resolved.
  • Avoid testing vulnerabilities in a way that could disrupt services.
  • Act in good faith and with respect for user data and privacy.

๐Ÿง  Security Best Practices for Contributors

If you're contributing code to the project, please keep these in mind:

  • Avoid hardcoding secrets or tokens in the codebase.
  • Sanitize and validate all user input.
  • Keep dependencies up to date.
  • Run security linters or scans (e.g., bandit for Python).
  • Use HTTPS and secure data handling practices when applicable.

๐Ÿ™ Acknowledgments

We appreciate the communityโ€™s support in improving the security of EventStack. Thank you for acting responsibly and helping make open source better and safer for everyone.

=======

Security Policy

Supported Versions

We currently support and maintain the following versions of this project:

Version Supported
Latest โœ…
Older โŒ (no longer maintained)

If you are using an older version, we recommend upgrading to the latest release for security and stability.


Reporting a Vulnerability

If you discover a security vulnerability, we encourage you to report it privately and responsibly to help us maintain a secure project.

๐Ÿ“ง Preferred Contact Method:

Please email us at [email protected] with the following details:

  • Description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact (if known)
  • Any relevant screenshots, logs, or PoC (Proof of Concept)

Note: Do not publicly disclose the vulnerability until it has been investigated and resolved.

Alternatively, you may use GitHubโ€™s built-in Security Advisories feature to report issues.


Response Timeline

We aim to respond to vulnerability reports within 72 hours of receipt. Depending on the severity and complexity of the issue, we may take longer to provide a fix.

You will be notified:

  • Upon receipt of your report
  • When the investigation is complete
  • Once a fix is implemented and released
  • When public disclosure is appropriate

Acknowledgements

We sincerely thank all contributors and researchers who help keep this project secure.


Thank you for helping us improve the security of this project!

There arenโ€™t any published security advisories