Skip to content

Security: sszczep/homeassistant-grenton

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security issue, we strongly encourage you to report it responsibly and privately.

📧 How to Report

Please send all vulnerability reports to:

contact@sszczep.dev

Alternatively, you may open a private security advisory through the project’s GitHub repository:

https://github.com/sszczep/homeassistant-grenton/security/advisories

🔒 Responsible Disclosure

Please do not publicly disclose the vulnerability before we have confirmed and addressed it.
Early disclosure may put existing users at risk.

🛠 Security Issue Handling

Once a vulnerability is confirmed:

  1. We assign a severity rating (Low / Medium / High / Critical)
  2. We begin patch development for firmware, or documentation
  3. We prepare a coordinated disclosure timeline with you
  4. A fix is published along with a security advisory
  5. Credits are provided to reporters (optional and only with consent)

🧪 What to Include in Your Report

To help us investigate efficiently, please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Affected firmware version
  • Expected behavior vs actual behavior
  • Impact assessment (if known)
  • Any proof-of-concept code, test scripts

🙏 Thank You

We appreciate the work of security researchers and users who help improve the safety of the project.
Responsible disclosure ensures the project remains reliable in industrial and automation environments.

There aren’t any published security advisories