| Version | Supported |
|---|---|
| latest | ✅ |
If you discover a security vulnerability in this project, please report it responsibly.
- Do NOT create a public GitHub issue for security vulnerabilities
- Email: rhodium-standard@proton.me
- Or use GitHub's private vulnerability reporting if enabled
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (optional)
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 7 days
- Resolution Target: Within 30 days for critical issues
- Acknowledgment of your report
- Regular updates on progress
- Credit in release notes (unless you prefer anonymity)
- Coordinated disclosure timeline
- All GitHub Actions pinned to SHA hashes
- SPDX license headers on source files
- Dependency auditing via Scorecard
- HTTPS only for all external URLs
- No hardcoded secrets
- Automated secret scanning via TruffleHog
This security policy applies to:
- This repository and official releases
- Documentation
- Third-party forks or modifications
- Vulnerabilities in dependencies (report to respective maintainers)