Skip to content

Security: gregPerlinLi/CertVault

Security

SECURITY.md

Reporting Security Issues

The CertVault team takes security bugs seriously. We appreciate your efforts to responsibly disclose findings and will acknowledge your contributions.

How to Report a Security Issue

  1. Use the GitHub Security Advisory "Report a Vulnerability" form
  2. For third-party module vulnerabilities, contact the module maintainer or use the npm security contact form for npm libraries or Maven Security Advisory for Maven libraries
  3. Critical issues can also be reported via email to: lihaolin13@outlook.com

What to Expect

  • Initial response within 24-48 hours
  • Periodic updates during investigation/patching
  • Coordinated public disclosure after patch release
  • CVE assignment for confirmed vulnerabilities

Security Notification Process

For details on our security notification flow, see our Security WG Governance Docs.

Security Research Resources

⚠️ Never disclose sensitive security details in public GitHub issues or discussions

There aren’t any published security advisories