Skip to content

Security: rafidhp/kangru

Security

SECURITY.md

Security Reporting

If you wish to report a security vulnerability, we ask that you follow the following process, which complies with the Open Source Committee Maintainers Manual.

Please fill out the following template:

Please report security vulnerabilities by providing the following information:

  • PROJECT: A URL to project's repository
  • PUBLIC: Please let us know if this vulnerability has been made or discussed publicly already. If so, please let us know where.
  • DESCRIPTION: Please provide precise description of the security vulnerability you have found with as much information that you are able and willing to provide.

Please send the above info, along with any other information you feel is pertinent to: rafidhp.

In addition, you may request that the project provide you a patched release in advance of the release announcement. However, we cannot guarantee that such information will be provided to you in advance of the public release and announcement. However, the Kangru team will email you at the same time the public announcement is made.

The Kangru team will let you know within two business weeks whether or not your report has been accepted or rejected. We ask that you please keep the report confidential until we have made a public announcement.

There aren't any published security advisories