Skip to content

Security: wgo-audit/.github

Security

.github/SECURITY.md

Security Policy

We take the security of this project seriously. If you believe you have found a security vulnerability, please report it to us responsibly using the instructions below.

Supported Versions

Only the latest tagged release and active development branch main receive security updates.

Reporting a Vulnerability

⚠️ Do NOT open public GitHub issues, discussions, or pull requests for security vulnerabilities.

Preferred Method: Private Vulnerability Reporting

Please submit reports directly via GitHub Private Vulnerability Reporting:

  1. Go to the repository's Security tab
  2. In the left sidebar, click Reporting
  3. Click Report a vulnerability to open the advisory form

What to Include in Your Report

To help us triage and resolve the issue quickly, please include:

  • Description: A brief summary of the type of vulnerability (e.g., injection, privilege escalation)
  • Location: Affected files, functions, or dependencies
  • Reproduction Steps: Step-by-step instructions or proof-of-concept code
  • Impact: What an attacker could achieve if the issue is exploited

Response & Disclosure Process

  • Acknowledgment: We will acknowledge receipt of your report within 72 hours
  • Investigation: We will evaluate the report and communicate progress via the private GitHub Advisory thread
  • Fix & Release: Once a fix is verified, we will issue an update and coordinate a public Security Advisory, crediting your contribution if desired

There aren't any published security advisories