Vulnerability reporting policy scored to Scorecard Security-Policy 10/10: contact email, canonical repo URL with https://, response process, and a supported-versions table reflecting the actual v1.1.0 tag (only 1.x line exists). No docs/support-period.md or SBOM claims — neither exists in this repo.
905 B
905 B
Security policy
Reporting a vulnerability
Report privately to security@fromaitochitta.com - do not open a public issue. Canonical repository: https://git.fromaitochitta.com/open/human-friendly-style
Please include the affected version or commit, a minimal reproduction, and the impact you see. We acknowledge every report within 5 working days, agree a fix and disclosure timeline with the reporter, and aim to disclose within 90 days of the initial report.
Response process
- Acknowledge within 5 working days.
- Triage and confirm severity within 10 working days.
- Develop and test a fix.
- Publish an advisory and credit the reporter unless they prefer to remain anonymous.
Supported versions
| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
Advisories
Security-relevant changes are noted in CHANGELOG.md.