Files
2026-08-16 21:52:42 +10:00

26 lines
1.0 KiB
Markdown

# Security policy
## Supported versions
Security fixes are made for the latest released package version. While the SDK
is pre-1.0, upgrade to the latest beta before reporting a suspected issue.
## Reporting a vulnerability
Please report vulnerabilities privately through
[GitHub Security Advisories](https://github.com/alexhopeoconnor/binarylane-dotnet/security/advisories/new).
If private reporting is unavailable, open a minimal public issue that asks for
a private contact channel and does not disclose exploit details.
Do not include any of the following in a report, issue, pull request, log, or
sample:
- BinaryLane bearer tokens or authorization headers;
- account email addresses, invoices, or billing data;
- passwords, password reset payloads, SSH private keys, or `user_data`;
- private IP addresses, server names, DNS records, or raw response bodies that
are not essential to demonstrate the problem.
Maintainers aim to acknowledge a report within seven days and will coordinate
a fix and disclosure timeline with the reporter.