Skip to content

Security: runtimebug/retroloop

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in RetroLoop, please report it responsibly. Do not open a public GitHub issue.

Instead, report vulnerabilities via GitHub Security Advisories.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Affected versions or components
  • Potential impact
  • Suggested fix (if any)

Response Timeline

Step Timeframe
Acknowledgment Within 48 hours
Initial evaluation Within 7 days
Fix and disclosure Coordinated with reporter

Supported Versions

Version Supported
Latest release Yes
Older releases No

Disclosure Policy

We follow a responsible disclosure process:

  1. Reporter submits vulnerability privately
  2. We acknowledge receipt within 48 hours
  3. We evaluate severity and impact within 7 days
  4. We develop and test a fix
  5. We release the fix and publish a security advisory
  6. Reporter is credited (unless they prefer anonymity)

We ask that you give us reasonable time to address the issue before any public disclosure.

There aren’t any published security advisories