Skip to content

Security: ehtishammubarik/stackmason

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Email ehtisham@eprecisio.com with the details. Please do not open a public issue for a security problem.

Useful things to include:

  • What the issue is and where it lives, with file paths or endpoints.
  • Steps to reproduce, or a proof of concept.
  • What an attacker gains, and what they need in order to exploit it.
  • Any suggested fix, if you have one.

What to expect

Stage Target
Acknowledgement Within 3 working days
Initial assessment Within 7 working days
Fix or mitigation plan Communicated once assessed, with a realistic date

These are personal and consultancy repositories, not a funded product, so I will be honest with you about timelines rather than promise a schedule I cannot hold.

Scope

Reports are welcome on anything in a repository I own. Exposed credentials, injection paths, privilege escalation, and insecure defaults in infrastructure code are all in scope and all appreciated.

If you find a credential of mine committed anywhere, please report it directly rather than opening a public issue. I will rotate it at the provider first and clean the history second, in that order.

Disclosure

Coordinated disclosure. Tell me first, give me a reasonable window to fix it, and I will credit you in the fix unless you would rather stay anonymous.

There aren't any published security advisories