Malbasert policy med security@fromaitochitta.com og https://-prefikset Forgejo-URL. Ingen versjonstabell-løgn: repoet har ingen tagger, det er skrevet eksplisitt. Ingen dødreferanser (docs/support-period.md finnes ikke). Ingen SBOM-løfte (repoet produserer ingen).
31 lines
981 B
Markdown
31 lines
981 B
Markdown
# Security policy
|
|
|
|
## Reporting a vulnerability
|
|
|
|
Report privately to <security@fromaitochitta.com> - do not open a
|
|
public issue.
|
|
Canonical repository: https://git.fromaitochitta.com/open/app-creator
|
|
|
|
Please include the affected version or commit, a minimal reproduction,
|
|
and the impact you see. We acknowledge every report within 5 working
|
|
days, agree a fix and disclosure timeline with the reporter, and aim to
|
|
disclose within 90 days of the initial report.
|
|
|
|
## Response process
|
|
|
|
1. Acknowledge within 5 working days.
|
|
2. Triage and confirm severity within 10 working days.
|
|
3. Develop and test a fix.
|
|
4. Publish an advisory and credit the reporter unless they prefer
|
|
to remain anonymous.
|
|
|
|
## Supported versions
|
|
|
|
This repository has no tagged releases yet; security fixes land on main.
|
|
It is also pre-design: no implementation code has shipped, per
|
|
`CLAUDE.md`.
|
|
|
|
## Advisories
|
|
|
|
No advisories have been published. Notable security-relevant changes
|
|
are recorded in `CHANGELOG.md`.
|