Skip to content

Security: r-bart/devtronic

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x
< 1.0

Reporting a Vulnerability

Please do NOT report security vulnerabilities through public GitHub issues.

Instead, use GitHub Security Advisories to report vulnerabilities privately.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Impact assessment
  • Suggested fix (if any)

Response Timeline

Stage SLA
Acknowledgment 48 hours
Assessment 5 business days
Fix (critical) 7 days
Fix (other) 30 days

Scope

This policy covers:

  • devtronic CLI package (packages/cli/)

This policy does not cover:

  • Projects generated by devtronic (user responsibility)
  • Third-party dependencies (report upstream)

Disclosure Policy

We follow coordinated disclosure:

  1. Reporter submits vulnerability privately
  2. We acknowledge and assess
  3. We develop and test a fix
  4. We release the fix and publish an advisory
  5. Reporter receives credit (unless they prefer anonymity)

Thank you for helping keep devtronic and its users safe.

There aren't any published security advisories