Skip to content

Security: NEO1842/Submodule-Forge

SECURITY.md

πŸ›‘ Security Policy

πŸ“¦ Supported Versions

The following versions of Submodule-Forge are currently supported with security updates:

Version Supported
1.1.x βœ…
1.0.x ⚠️ Limited
< 1.0 ❌
  • βœ… Fully supported (receives security updates)
  • ⚠️ Critical fixes only
  • ❌ Not supported

🚨 Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly.

πŸ“© How to Report

  • Open a private report (preferred)
  • Or contact via GitHub (Issues are allowed, but avoid posting sensitive details publicly)

⏱ Response Time

  • Initial response: within 48 hours
  • Status updates: as needed
  • Fix release: depends on severity

πŸ” What to Expect

βœ… If accepted:

  • The issue will be investigated
  • A fix will be prepared
  • A new release will be published

❌ If declined:

  • You will receive an explanation
  • Suggestions or alternatives may be provided

πŸ”’ Security Notes

  • Always use dependencies from trusted sources
  • Keep your environment updated
  • Avoid exposing sensitive data in repositories

πŸ™ Responsible Disclosure

Please do not publicly disclose vulnerabilities until they have been reviewed and fixed.

Thank you for helping keep Submodule-Forge secure πŸ™Œ

There aren't any published security advisories