Skip to content

Security: astrostl/pentameter

SECURITY.md

Security Policy

Important Notice

No Warranties or Guarantees: This project is provided "as is" without any warranty or guarantee of security, functionality, or reliability. Please review the code thoroughly before using in any environment.

Security Commitment

While this project comes with no warranties, we take security seriously and are committed to addressing security issues promptly and responsibly.

Reporting Security Issues

If you discover a security vulnerability or potential security issue:

  1. Do NOT create a public issue - This could expose the vulnerability to potential attackers
  2. File a private issue or contact the maintainers directly
  3. Do NOT include sensitive information such as:
    • Your actual IP addresses
    • Network configuration details
    • Pool controller credentials or API keys
    • Any production system information

What to Include

When reporting a security issue, please provide:

  • A clear description of the potential vulnerability
  • Steps to reproduce (using generic examples)
  • Potential impact assessment
  • Any suggested mitigations you've identified

Our Response

  • We will acknowledge receipt of security reports promptly
  • We will investigate all legitimate security concerns
  • We will communicate with you throughout the process
  • We will coordinate public disclosure timing with you when appropriate

Scope

This security policy covers:

  • The Pentameter application code
  • Docker configuration and deployment
  • Documentation that might impact security

Contact

For security issues, please use GitHub's private vulnerability reporting feature or open a regular issue with "SECURITY" in the title (without including sensitive details).

Thank you for helping keep Pentameter secure.

There aren’t any published security advisories