The accountable security owner for this repository is Crown Social Agency (@crown-social-agency). Reports may be sent privately to hello@crownsocialagency.com.
Do not disclose suspected vulnerabilities in a public issue before the owner has assessed and remediated them.
| Severity | Acknowledge and triage | Remediate or document mitigation |
|---|---|---|
| Critical | Within 24 hours | Within 72 hours |
| High | Within 7 calendar days | Within 30 calendar days |
| Moderate | Within 30 calendar days | In the next planned maintenance cycle |
| Low | Best effort | As prioritized |
These are operational response targets, not guarantees. If a deadline cannot be met, the owner must document the risk, compensating controls, accountable person, and next review date.
The default branch and currently deployed production release receive security fixes. Archived branches and superseded releases are unsupported unless explicitly documented otherwise.