Skip to content

Security: ryanduguid/standards-testing

SECURITY.md

Security policy

Supported versions

Security fixes are applied to the latest version on the default branch.

Reporting a vulnerability

Use the affected repository's private vulnerability-reporting feature, under Security then Report a vulnerability. Do not open a public issue or pull request for a suspected vulnerability.

That feature is not available on every repository. Where the repository's Security tab offers no Report a vulnerability button, email ryan@duguid.com.au instead, with SECURITY in the subject line. Email is unencrypted, so send only what the next paragraph permits and wait for a private channel before sending anything more.

Most of the repositories without the feature are contribution forks of upstream projects. A vulnerability in the upstream code belongs to that project's own security policy, so report it there; use the address above only for something introduced by this account's changes.

Include a clear description, reproduction steps using fabricated data, likely impact, and any suggested mitigation. Never include client, taxpayer, employee, payroll, access-token or other sensitive data.

We will acknowledge a valid report within 7 days and coordinate the fix and disclosure timeline with the reporter.

If a repository has its own SECURITY.md, that repository-specific policy takes precedence over this account-level default.

There aren't any published security advisories