Skip to content

Security: sachncs/hurstify

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.1.x
2.0.x
1.x.x

Reporting a Vulnerability

If you discover a security vulnerability within hurstify, please send an email to the maintainers via GitHub Issues. All security vulnerabilities will be promptly addressed.

Please do NOT report security vulnerabilities through public GitHub issues.

What to Include

When reporting a vulnerability, please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • The version(s) of hurstify affected
  • Any potential mitigations you have identified

Response Expectations

  • Acknowledgment: We will acknowledge receipt of your report within 48 hours.
  • Assessment: We will investigate and validate the report within 7 business days.
  • Resolution: We will work on a fix and coordinate disclosure with you.
  • Disclosure: We will publish a security advisory once the fix is released.

Disclosure Policy

  • We request that you give us a reasonable amount of time to address the issue before public disclosure.
  • We will credit reporters in the security advisory unless they prefer to remain anonymous.
  • We will not take legal action against researchers who report vulnerabilities in good faith.

Security Best Practices

  • Always use the latest version of hurstify.
  • Review the CHANGELOG.md for security-related updates.
  • When using RK-SAVR in production, ensure your environment is properly secured.
  • Do not expose internal endpoints or debugging interfaces in production.

Dependencies

We use Dependabot to keep dependencies up to date. Security patches are applied promptly.

Contact

For any security concerns, please open a private issue or contact the maintainers directly.

There aren't any published security advisories