Skip to content

Latest commit

 

History

History
47 lines (30 loc) · 1.46 KB

File metadata and controls

47 lines (30 loc) · 1.46 KB

Security Policy

Supported Versions

Version Supported
Latest release Yes
Previous releases No

We recommend always using the latest version of abap2UI5.

Reporting a Vulnerability

We take security issues seriously. If you discover a security vulnerability, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please use the GitHub Security Advisory "Report a Vulnerability" tab.

What to Include

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 3 business days
  • Initial assessment: Within 7 business days
  • Resolution target: Depends on severity, typically within 30 days

Process

  1. Report the vulnerability via GitHub Security Advisory
  2. We will acknowledge receipt and begin investigation
  3. We will work with you to understand and validate the issue
  4. A fix will be developed and tested
  5. A security advisory will be published with the fix release

Scope

This policy applies to the abap2UI5 core framework (src/ directory). For vulnerabilities in dependencies or related repositories, please report them to the respective maintainers.

Credit

We appreciate responsible disclosure and will credit reporters in the security advisory (unless you prefer to remain anonymous).