Skip to content

Security: Project-Colony/SAM-Colony-Edition

SECURITY.md

Security Policy

This policy applies to every repository in the Project-Colony organization that does not ship its own SECURITY.md.

Reporting a vulnerability

Please do not report security vulnerabilities through public issues, pull requests or discussions.

Report them privately instead, on the affected repository:

  1. Open the repository on GitHub.
  2. Go to the Security tab.
  3. Click Report a vulnerability and fill in the form.

Only the maintainers can see the report. Please include:

  • the affected app and version (or commit),
  • your platform (distribution, Windows or macOS version),
  • what an attacker can do, and the steps to reproduce it,
  • a proof of concept, if you have one.

If you are not sure which repository is affected, report it on Colony.

What to expect

We will acknowledge the report, keep you informed while we work on it, and credit you in the advisory once a fix is released, unless you prefer to stay anonymous.

Supported versions

Only the latest release of each app receives security fixes. Linux is the supported platform; reports against the best-effort Windows and macOS builds are welcome and handled the same way.

There aren't any published security advisories