mirror of
https://github.com/alexhopeoconnor/binarylane-dotnet.git
synced 2026-10-04 02:18:11 +10:00
26 lines
1.0 KiB
Markdown
26 lines
1.0 KiB
Markdown
# Security policy
|
|
|
|
## Supported versions
|
|
|
|
Security fixes are made for the latest released package version. While the SDK
|
|
is pre-1.0, upgrade to the latest beta before reporting a suspected issue.
|
|
|
|
## Reporting a vulnerability
|
|
|
|
Please report vulnerabilities privately through
|
|
[GitHub Security Advisories](https://github.com/alexhopeoconnor/binarylane-dotnet/security/advisories/new).
|
|
If private reporting is unavailable, open a minimal public issue that asks for
|
|
a private contact channel and does not disclose exploit details.
|
|
|
|
Do not include any of the following in a report, issue, pull request, log, or
|
|
sample:
|
|
|
|
- BinaryLane bearer tokens or authorization headers;
|
|
- account email addresses, invoices, or billing data;
|
|
- passwords, password reset payloads, SSH private keys, or `user_data`;
|
|
- private IP addresses, server names, DNS records, or raw response bodies that
|
|
are not essential to demonstrate the problem.
|
|
|
|
Maintainers aim to acknowledge a report within seven days and will coordinate
|
|
a fix and disclosure timeline with the reporter.
|