Skip to content

Security: trsdn/PtionsPlus

SECURITY.md

Security Policy

This policy applies to trsdn projects that do not publish their own security policy.

Supported versions

The latest release and the current default branch are supported. Older releases are not patched unless the project states otherwise.

Report a vulnerability privately

Use the affected repository's Security tab and choose Report a vulnerability. This opens a private advisory that only maintainers can see. If private reporting is unavailable there, open an issue asking for a private channel and leave out exploit details.

Please include:

  • the affected version, commit, or release;
  • impact and a realistic attack scenario;
  • minimal reproduction steps or a proof of concept;
  • a suggested fix, if you have one.

Do not disclose details publicly before a fix is available, and never include working credentials, tokens, or personal data in a report.

What to expect

Reports are triaged privately. Confirmed issues are fixed on a timeline that matches their severity, and reporters are credited on request once a fix ships.

There aren't any published security advisories