Skip to content

Security: superloglabs/responder-oss

SECURITY.md

Security policy

We take the security of Responder and its users seriously.

Supported versions

Security fixes are applied to the latest release and the current main branch. Older commits and tags are not patched.

Reporting a vulnerability

Do not report security vulnerabilities through public issues, pull requests, or community chat.

Use GitHub's private vulnerability reporting from the repository Security tab:

https://github.com/superloglabs/responder-oss/security/advisories/new

If that is unavailable, email security@superlog.sh.

Please include the affected component and version, reproduction steps, impact, and a proof of concept when possible. We aim to acknowledge reports within three business days and provide an initial assessment within seven business days. We will coordinate disclosure after a fix is available and credit the reporter unless they prefer otherwise.

Scope

This policy covers the code in this repository and the hosted Responder service. Reports from automated scanners should include a demonstrated security impact. Publicly known vulnerable dependencies without an application-specific impact can be reported as a normal dependency update.

Safe harbor

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable time to fix an issue before disclosure.

There aren't any published security advisories