Skip to content

Security: AET-DevOps25/w09-solution

Security

.github/SECURITY.md

Security Policy

Supported Versions

Here are the supported versions of this application

Version Supported
1.0.0
< 1.0

It is worth noting we also publish container images as packages of each service. For those, refer to this:

Tag Supported
main
all else

Reporting a Vulnerability

We take the security of our project seriously. If you believe you have found a security vulnerability, please follow these steps:

  1. DO NOT disclose the vulnerability publicly until it has been addressed by our team
  2. Email your findings to [email protected]
  3. Include the following information in your report:
    • Description of the vulnerability
    • Steps to reproduce the issue: docker can ensure your steps are conveniently reproducible on our machines as well
    • Potential impact
    • Any possible solutions you've identified

What to expect

  • We will acknowledge receipt of your vulnerability report within 48 hours
  • We will provide a detailed response within 5 business days
  • We will keep you informed about the progress towards fixing and disclosing the vulnerability
  • We will credit you for the discovery (unless you prefer to remain anonymous)

Security Updates

Security updates will be released as follows:

  • Critical vulnerabilities: Within 24 hours
  • High severity: Within 7 days
  • Medium/Low severity: Next release cycle

Security-Related Configuration

Include any security-relevant configuration information here, such as:

  • Recommended security settings
  • Authentication setup
  • Access control configuration

Known Security Gaps and Future Enhancements

Document any known security limitations and planned improvements:

  • Current limitations
  • Planned security features
  • Future security roadmap

Security Contacts

There aren’t any published security advisories