Use this intake order for all security reports:
- GitHub Private Vulnerability Reporting for this repository
- Report at Sonicverse Security
- Do not use public GitHub issues for security-sensitive reports
Public GitHub issues can expose users, deployments, or maintainers before a fix is available, so please use a private reporting channel.
To help us validate and respond efficiently, please include:
- A clear summary of the issue and the affected component or file path
- Steps to reproduce the problem
- The potential impact, including what an attacker could do
- Any proof of concept, logs, screenshots, or sample requests that help demonstrate the issue
- Version, environment, commit hash, or deployment details if relevant
- Your name or preferred contact details for follow-up
Please avoid accessing, modifying, or retaining other people's data while testing. If you believe sensitive data may have been exposed, stop testing and tell us immediately in your report.
We aim to handle reports using the following timeline:
- Acknowledgment within 3 business days
- Initial triage and severity assessment within 7 business days
- A follow-up status update within 14 business days after triage
- Ongoing updates at reasonable intervals until the issue is resolved or a mitigation is available
Our handling process is generally:
- Confirm receipt of the report
- Validate and reproduce the issue
- Assess severity, scope, and affected systems
- Prepare a fix or mitigation
- Coordinate release timing and disclosure with the reporter when appropriate
Response and resolution times can vary depending on the complexity and impact of the issue, but we will communicate progress as clearly as possible.
We ask for coordinated disclosure. Please do not publicly disclose the vulnerability until:
- We confirm that a fix or mitigation is available, or
- We agree on a public disclosure timeline together
When a report is confirmed, we may publish a security advisory, release notes, or other public notice once users have had a reasonable opportunity to update or mitigate.
This policy applies to this repository and related deployment or runtime behavior directly associated with the Sonicverse website project.