No Warranties or Guarantees: This project is provided "as is" without any warranty or guarantee of security, functionality, or reliability. Please review the code thoroughly before using in any environment.
While this project comes with no warranties, we take security seriously and are committed to addressing security issues promptly and responsibly.
If you discover a security vulnerability or potential security issue:
- Do NOT create a public issue - This could expose the vulnerability to potential attackers
- File a private issue or contact the maintainers directly
- Do NOT include sensitive information such as:
- Your actual IP addresses
- Network configuration details
- Pool controller credentials or API keys
- Any production system information
When reporting a security issue, please provide:
- A clear description of the potential vulnerability
- Steps to reproduce (using generic examples)
- Potential impact assessment
- Any suggested mitigations you've identified
- We will acknowledge receipt of security reports promptly
- We will investigate all legitimate security concerns
- We will communicate with you throughout the process
- We will coordinate public disclosure timing with you when appropriate
This security policy covers:
- The Pentameter application code
- Docker configuration and deployment
- Documentation that might impact security
For security issues, please use GitHub's private vulnerability reporting feature or open a regular issue with "SECURITY" in the title (without including sensitive details).
Thank you for helping keep Pentameter secure.