Skip to content

Security: MSeys/ProtoTest

SECURITY.md

Security policy

Supported versions

Security fixes are made against the latest stable release. Users should reproduce an issue on the newest ProtoTest packages before reporting it.

Reporting a vulnerability

Please do not open a public issue containing exploit details, credentials, private trace data or other sensitive material. Use GitHub's Report a vulnerability flow on the repository's Security tab to start a private report with the maintainer. If that control is unavailable, contact the maintainer privately through the contact route on the project owner's GitHub profile.

Include the affected package and version, impact, reproduction steps and any suggested mitigation. Share only the minimum artifact needed to demonstrate the issue; a .prototrace can contain application data and attachments.

You can expect acknowledgement when the report is seen, followed by an assessment of scope and next steps. Public disclosure should wait until a fix or safe mitigation is available.

There aren't any published security advisories