This policy applies to all public repositories of Das Digitale Momentum that do not ship their own SECURITY.md.
Security fixes are made on the default branch and, where a project publishes releases, in the next release. Older releases are not patched.
Please do not open a public issue, discussion or pull request for a suspected vulnerability.
Report it privately instead:
- GitHub private vulnerability reporting (preferred): open the affected repository, go to Security → Advisories → Report a vulnerability. This creates a private draft advisory that only you and the maintainers can see.
- Email: if you cannot use GitHub, write to info@ddm-it.de with the subject line
Security: <repository name>.
Please include:
- the affected repository and version or commit,
- a description of the issue and its impact,
- steps to reproduce or a proof of concept,
- whether and how you would like to be credited.
We confirm receipt, assess the report, and keep you informed while we work on a fix. Once a fix is available we publish a GitHub Security Advisory and credit you unless you ask us not to. Please give us a reasonable amount of time to release a fix before disclosing the issue publicly.