human-friendly-style/SECURITY.md
Kjell Tore Guttormsen 2427d36e7e docs: add SECURITY.md (AAA+ C-axis, ORDRE 36)
Vulnerability reporting policy scored to Scorecard Security-Policy 10/10:
contact email, canonical repo URL with https://, response process, and
a supported-versions table reflecting the actual v1.1.0 tag (only 1.x
line exists). No docs/support-period.md or SBOM claims — neither exists
in this repo.
2026-08-16 21:14:32 +02:00

905 B

Security policy

Reporting a vulnerability

Report privately to security@fromaitochitta.com - do not open a public issue. Canonical repository: https://git.fromaitochitta.com/open/human-friendly-style

Please include the affected version or commit, a minimal reproduction, and the impact you see. We acknowledge every report within 5 working days, agree a fix and disclosure timeline with the reporter, and aim to disclose within 90 days of the initial report.

Response process

  1. Acknowledge within 5 working days.
  2. Triage and confirm severity within 10 working days.
  3. Develop and test a fix.
  4. Publish an advisory and credit the reporter unless they prefer to remain anonymous.

Supported versions

Version Supported
1.x Yes
< 1.0 No

Advisories

Security-relevant changes are noted in CHANGELOG.md.