Skip to content

Security: alganet/PHL

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in PHL, please help us by reporting it responsibly.

Do not report security vulnerabilities through public GitHub issues.

Instead, please report security vulnerabilities by emailing the maintainers at:

Include the following information in your report:

  • A clear description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact and severity
  • Any suggested fixes or mitigations

Response Process

  1. Acknowledgment: We will acknowledge receipt of your report within a working week
  2. Investigation: We will investigate the issue and determine its validity
  3. Updates: We will provide regular updates on our progress (at least weekly)
  4. Resolution: Once resolved, we will:
    • Create a fix
    • Publicly disclose the vulnerability after giving users time to update

Disclosure Policy

  • We follow responsible disclosure practices
  • We will not publicly disclose vulnerabilities until a fix is available
  • We will credit reporters (with permission) in security advisories
  • We aim to resolve critical security issues within 90 days

Safe Harbor

We appreciate security researchers helping keep PHL safe. As long as you follow this policy and act in good faith, we will not take legal action against you for security research activities.

Contact

For security-related questions or concerns, contact the maintainers through the email address above.

There aren’t any published security advisories