Skip to content

Security: refined-element/l402-requests

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public GitHub issue for a suspected security vulnerability.

Use this repository's GitHub Private Vulnerability Reporting / security-advisory flow to report vulnerabilities privately. If private reporting is unavailable for a particular repository, open a private security advisory from that repository's Security tab.

Please include:

  • affected repository, version, release, or commit SHA;
  • a clear description of the issue and its potential impact;
  • reproducible steps or a minimal proof of concept, where safe; and
  • any proposed mitigation or patch, if available.

Keep secrets out of reports

Do not include private keys, seed phrases, wallet credentials, NWC connection strings, macaroons, payment preimages, API keys, access tokens, invoices, customer data, or other sensitive production material in a report.

Use redacted examples or contact us through the private advisory to arrange a safe reproduction path when necessary.

Scope

This policy covers security vulnerabilities in maintained public repositories owned by refined-element that do not provide a more specific repository-level SECURITY.md.

It does not cover third-party services, third-party wallet providers, independently deployed applications, or vulnerabilities that cannot be reproduced in maintained refined-element code or official releases.

Supported versions

Security fixes are normally provided for the latest released version. Where practical, we may provide mitigations for supported release branches; older releases may require an upgrade.

Response and coordinated disclosure

We aim to acknowledge valid reports within five business days and will assess impact, work toward a fix or mitigation, and coordinate public disclosure after affected users have had a reasonable opportunity to update.

Please do not publicly disclose a suspected vulnerability before coordinated disclosure or before we have agreed that disclosure is appropriate.

Good-faith research

We welcome good-faith security research. Please avoid actions that could harm users, disrupt services, access data you do not own, or create costs or payments for others.

There aren't any published security advisories