Skip to content

Security: kratecorg/mapre

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please report security issues privately and do not disclose them in a public issue, pull request, or discussion.

Use one of the following channels:

  • the repository's GitHub Security Advisories page for this project, if available
  • a private report to the maintainers through the project contact channel

If you are unsure how to report it, open a normal issue only for non-sensitive questions and use the private security reporting path for suspected vulnerabilities.

What to include

When reporting a vulnerability, please include:

  • a clear description of the issue and affected behavior
  • the component, version, or commit involved
  • reproduction steps or a minimal proof of concept
  • the impact and potential severity
  • any suggested mitigation or fix

Response expectations

We aim to review private reports promptly and will do our best to confirm receipt, assess severity, and coordinate remediation.

Disclosure policy

We ask researchers and users to allow a reasonable amount of time for a fix to be prepared before public disclosure, especially when the issue affects production use. We prefer coordinated disclosure and will work with reporters to address the problem responsibly.

Supported versions

This project is under active development. We recommend using the latest released version or the newest available commit on the default branch.

There aren't any published security advisories