Skip to content

Security: Keayoub/pvw-cli

SECURITY.md

Security Policy

Reporting Vulnerabilities

Do not report security issues in public GitHub issues, pull requests, or discussions.

Send vulnerability reports to:

Include the following details when possible:

  1. Vulnerability title and summary
  2. Affected component and versions
  3. Reproduction steps or proof of concept
  4. Impact assessment and possible exploitability
  5. Suggested mitigations (optional)

Responsible Disclosure Expectations

We expect coordinated and responsible disclosure:

  1. Give the maintainers a reasonable opportunity to investigate and remediate.
  2. Avoid public disclosure until a fix or mitigation is available.
  3. Do not access, modify, or exfiltrate data beyond what is needed to demonstrate the issue.
  4. Do not perform destructive testing or service disruption.

Response Expectations

The project aims to follow this response timeline:

  1. Acknowledgment within 3 business days
  2. Initial triage and severity assessment within 7 business days
  3. Periodic status updates during remediation
  4. Public disclosure and release notes after remediation, when appropriate

Response times may vary based on severity, impact, and maintainer availability.

Scope

This policy applies to security vulnerabilities in this repository and maintained releases.

Safe Harbor

Good-faith security research conducted under this policy and within applicable law is welcome.

There aren't any published security advisories