Skip to content

Security: freerware/negotiator

Security

SECURITY.md

Security Policy

Supported Versions

We release security patches for the following versions:

Version Supported
1.x.x

Reporting a Vulnerability

We take the security of this project seriously. If you discover a security vulnerability, please follow these steps:

  1. Do not open a public issue.

  2. Email your findings to the project maintainers.

  3. Include as much detail as possible:

    • Type of vulnerability
    • Full paths of source file(s) related to the issue
    • Location of the affected source code (tag/branch/commit or direct URL)
    • Any special configuration required to reproduce the issue
    • Step-by-step instructions to reproduce the issue
    • Proof-of-concept or exploit code (if possible)
    • Impact of the issue, including how an attacker might exploit it
  4. Allow us time to respond (typically within 48 hours).

Preferred Languages

We prefer all communications to be in English.

Security Update Process

  1. We will acknowledge your report within 48 hours.
  2. We will send a more detailed response within 72 hours.
  3. We will keep you informed of our progress.
  4. We will notify you when the vulnerability is fixed.
  5. We may ask for additional information or clarification.

Disclosure Policy

We follow a coordinated disclosure process:

  1. Security issue is reported
  2. Issue is investigated and fix is developed
  3. Fix is released
  4. Public disclosure occurs after 30 days from release

Thank you for helping keep this project secure!

There aren't any published security advisories