Skip to content

Security: BradGroux/influence-operating-framework

SECURITY.md

Security and Privacy

Purpose

This policy provides a private route for reporting credentials, personal or confidential information, unsafe publication, malicious repository behavior, or another security-sensitive condition affecting this repository.

It does not replace the Code of Conduct, contribution process, or appropriate professional and organizational incident-response procedures.

Supported Versions

The latest approved release and the current main branch receive security-sensitive corrections. Superseded versions may be corrected when the founding steward determines that the consequence warrants it.

Report Privately

Do not place credentials, personal information, private evidence, exploit instructions, confidential sources, or sensitive relationship details in a public issue, pull request, discussion, or appeal.

Use GitHub private vulnerability reporting. If it is unavailable, use a private contact route listed on the @BradGroux GitHub profile.

If neither route is immediately available, submit the private sensitive-disclosure contact request without credentials, names, evidence, contact details, exploit instructions, or other sensitive information. The public request is not a private reporting channel. Retain the sensitive material safely until a private route is established.

Include only what is necessary to establish:

  • the affected repository content or release;
  • the nature and likely consequence of the condition;
  • whether sensitive material may already be public;
  • safe reproduction or verification steps, when applicable;
  • containment already performed; and
  • a private way to continue the report.

Response and Disclosure

The founding steward or delegated maintainer will:

  1. acknowledge and contain the report through a private channel;
  2. preserve necessary evidence without unnecessarily copying sensitive material;
  3. assess affected content, versions, derivatives, and recipients;
  4. involve the appropriate privacy, security, legal, records, safety, or other authority when needed;
  5. correct, withdraw, rotate, or otherwise contain affected material;
  6. verify the correction and document the release effect; and
  7. coordinate any public disclosure so it does not increase harm.

No response-time guarantee, bug bounty, confidentiality contract, or safe-harbor term is created by this policy. The framework itself is not a security control, privacy program, legal opinion, or certification for an implementation.

There aren't any published security advisories