Skip to content

Security: Golm117/sigma

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
5.1.x
5.0.x
4.0.x
< 4.0

Project Scope & Educational Purpose Disclaimer

This project is maintained strictly for educational and research purposes. It is not intended for production use, commercial deployment, or any security-critical environment.

Vulnerability reports are welcomed and reviewed in good faith, but submission of a report does not guarantee that a fix, patch, or update will be issued. All reports may or may not influence future changes at the maintainer's sole discretion.

By submitting a report, you acknowledge that:

  • No service-level agreement (SLA) or guarantee of response is implied or provided
  • The maintainer reserves the right to accept, decline, defer, or take no action on any reported issue
  • This project carries no warranty, express or implied, regarding security, fitness for purpose, or reliability
  • Any use of this project in production or security-sensitive contexts is solely at the user's own risk

Reporting a Vulnerability

Please report security vulnerabilities privately. Do not open a public GitHub issue, as this could expose other users to risk before a fix is available.

How to report:

  • Preferred: Use GitHub's private vulnerability reporting — go to the Security tab of this repository and click Report a vulnerability
  • Alternative: Email the maintainer (contact listed on the repository owner's GitHub profile)

What to include in your report:

  • A clear description of the vulnerability
  • Steps to reproduce, including affected version(s)
  • Potential impact and severity assessment
  • Any proof-of-concept code or screenshots (if applicable)
  • Your preferred contact method and whether you wish to be credited

What to expect:

  • Acknowledgment of your report within 48 hours (best effort)
  • Initial status update within 7 days (best effort)
  • Communication on whether the report will or will not be acted upon
  • If accepted: a patch may be issued for supported versions, and you will be credited in release notes unless you request anonymity
  • If declined or deferred: a brief explanation will be provided where reasonable

Out of scope:

  • Vulnerabilities in third-party dependencies (report to the upstream maintainers)
  • Issues in unsupported versions (5.0.x, < 4.0)
  • Theoretical or hypothetical issues without demonstrable impact
  • Social engineering, physical access, or denial-of-service attacks against infrastructure unrelated to this codebase

Thank you for helping keep this project and its users safer.

There aren't any published security advisories