Skip to content

Security: moriturus/pinto

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest version on the default branch. Earlier versions are not maintained separately.

Reporting a vulnerability

Please do not file public issues for suspected vulnerabilities. Report them privately to the repository maintainer through GitHub's private vulnerability reporting feature. Include a clear description, reproduction steps, affected versions, and any suggested mitigation.

We aim to acknowledge reports within seven days. This is a response target, not a guarantee: timing can vary with severity, report completeness, maintainer availability, and the complexity of reproducing the issue. We will assess the impact and work with you on a fix and coordinated disclosure where appropriate.

Responsibilities and fallback

The security maintainer owns private intake, triage, reporter communication, and coordinated disclosure. The release maintainer owns versioning, changelog, package, tag, and publication checks for a security release. When one person holds both roles, the responsibilities remain separate in the review record.

A security fix or security release must record its risk assessment, responsible maintainer, strongest applicable tests and dependency checks, and disclosure or release follow-up actions in the private report or pull request. If one maintainer handles both intake and release, record that ownership explicitly. This is the fallback procedure; it does not change the response target into a guarantee or remove the need to document the decision.

There aren't any published security advisories