Skip to content

Security: bedrock-crustaceans/RAstra

Security

SECURITY.md

Security Policy

The RAstra team takes security seriously.
We appreciate the efforts of security researchers and community members who responsibly disclose vulnerabilities.


Supported Versions

Only the latest stable release of RAstra is actively supported with security updates.

Version Supported
Latest ✅ Yes
Older versions ❌ No

Please ensure you are running the most recent version before reporting an issue.


Reporting a Vulnerability

⚠️ Do not open public GitHub issues for security vulnerabilities.

If you discover a security issue, please report it responsibly by following the steps below.

How to report

Email:

📧 dev@bedrockcrustaceans.org

Include as much detail as possible:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected versions
  • Potential impact
  • Proof of concept (if available)

Response Process

Once a report is received:

  1. We will acknowledge your report as soon as possible.
  2. The issue will be investigated and validated.
  3. A fix will be developed and tested.
  4. A patched release will be published if necessary.
  5. Credit may be given upon request.

Please allow reasonable time for investigation and resolution.


Disclosure Policy

We kindly ask that you:

  • Do not publicly disclose the vulnerability before a fix is released
  • Do not exploit the issue beyond proof-of-concept testing
  • Act in good faith to protect users and servers

Responsible disclosure helps keep the RAstra ecosystem safe.


Thanks

Thank you for helping keep RAstra secure 💙
Your contributions are greatly appreciated.

There aren’t any published security advisories