You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We aim to respond within **3 business days**. During this time please keep the details confidential. We will work with you to validate and address the issue as quickly as possible.
17
+
18
+
## Security Practices
19
+
20
+
The project uses GitHub's security features:
21
+
22
+
-**Dependabot** for dependency updates and vulnerability alerts.
23
+
-**CodeQL** analysis and static scans on every push.
24
+
-**Bandit**, **Safety**, and **Trivy** scans during CI workflows.
25
+
26
+
## Disclosure Policy
27
+
28
+
We request a 90‑day period to remediate validated vulnerabilities before any public disclosure. After a fix is released we will credit you in the release notes if desired.
29
+
30
+
## Thank You
31
+
32
+
We appreciate the community's help in keeping this project secure.
0 commit comments