Skip to content

Security: heripo-lab/heripo-engine

Security

SECURITY.md

Security Policy

We take the security of this project seriously and appreciate responsible disclosures.

Supported Versions

We generally support the latest published version. Older versions may not receive security fixes.

Version Supported
latest yes
< latest no

Reporting a Vulnerability

Please do NOT open public GitHub issues for security vulnerabilities.

Provide as much detail as possible:

  • Affected version(s)
  • Environment (Node.js version, OS)
  • Reproduction steps or proof-of-concept
  • Impact assessment (what can an attacker achieve)

Disclosure Policy

  • We will acknowledge receipt within 3 business days.
  • We will investigate and provide an initial assessment within 7 business days.
  • We will work with you to validate, remediate, and coordinate a disclosure timeline.
  • We prefer coordinated disclosure; we will publish an advisory and release a patched version before public disclosure whenever possible.

Thank you for helping keep the community safe.

There aren’t any published security advisories