Publishes a vulnerability disclosure policy at the repo root, per the AAA+ program's C-axis (trust) sweep. Contact address and response timeline per operator decision; supported-versions section reflects that the catalog has no versioned release cycle and updates directly on main.
1.2 KiB
Security policy
Reporting a vulnerability
Report privately to security@fromaitochitta.com - do not open a public issue. Canonical repository: https://git.fromaitochitta.com/open/ktg-plugin-marketplace
Please include the affected version or commit, a minimal reproduction, and the impact you see. We acknowledge every report within 5 working days, agree a fix and disclosure timeline with the reporter, and aim to disclose within 90 days of the initial report.
Response process
- Acknowledge within 5 working days.
- Triage and confirm severity within 10 working days.
- Develop and test a fix.
- Publish an advisory and credit the reporter unless they prefer to remain anonymous.
Supported versions
This repository is the marketplace catalog manifest and does not follow a
versioned release cycle - it is continuously validated on every change
(scripts/check-versions.mjs) and updated directly on main. Security
fixes land on main; there are no separate maintained release lines to
track. Tags up to v7.7.2 predate the 2026 polyrepo split and are not an
active support line.
Advisories
This repository has no separate advisory feed or changelog. Fixes and their
history are visible directly in the main branch's git log.