Skip to content

Security: bmad-code-org/bmad-eval-quality

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Do NOT open a public GitHub issue.

Instead, report it privately through GitHub's private vulnerability reporting: Security > Report a vulnerability on this repository.

Please include, if possible:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested mitigation or fix (if known)

Response Process

After receiving a report, the maintainers will:

  1. Acknowledge receipt of the report
  2. Investigate the issue
  3. Determine severity and impact
  4. Develop and release a fix if necessary

We aim to respond within 5 business days.


Responsible Disclosure

We ask that security researchers:

  • Do not publicly disclose the vulnerability until a fix is available
  • Allow reasonable time for investigation and remediation
  • Avoid exploiting the vulnerability beyond what is necessary to demonstrate it

Supported Versions

Security updates are generally provided for the most recent release. Older versions may not receive security patches.


Security Updates

When a vulnerability is fixed, updates are published through the repository's release process and documented in the release notes.

There aren't any published security advisories