Skip to content

Security: Zutfen-LLC/zadc

SECURITY.md

Security Policy

Supported versions

ZADC is in PRE-ALPHA / BOOTSTRAP status. No stable release is available. Only the latest main branch and open pull requests are actively developed.

Security fixes will be applied to the latest main branch. No backport policy is in effect for pre-alpha software.

Reporting a vulnerability

We use GitHub private vulnerability reporting. Please do not publicly disclose security vulnerabilities.

To report a vulnerability:

  1. Navigate to https://github.com/Zutfen-LLC/zadc/security/advisories/new
  2. Create a private security advisory.
  3. Provide a clear description, reproduction steps, and impact assessment.

Alternatively, use the "Report a vulnerability" button on the Security advisories page.

Response expectations

  • We will acknowledge receipt of your report within 72 hours.
  • We will provide an initial assessment within 7 days.
  • We will coordinate disclosure timing with you.

What not to do

  • Do not publicly disclose vulnerabilities before coordination.
  • Do not commit secrets, API keys, tokens, or credentials to the repository.
  • Do not include credentials or sensitive data in issue reports, PRs, or commit messages.

There aren't any published security advisories