Skip to content

Security: draykerdk/uid

Security

SECURITY.md

Security policy

Scope

Many Drayker repositories contain research or architecture proposals rather than deployed software. A security claim in a paper is still open to review, but it must not be described as a vulnerability in an operational service unless such a service exists.

Deployed public scope currently includes the websites, documentation sites, their publishing workflows and reusable organization workflows.

Reporting

  1. Use the repository's private vulnerability-reporting feature when it is available.
  2. Otherwise open a minimal issue requesting a private channel. Do not include exploit details, credentials, personal data or unpublished keys.
  3. Include the affected repository, revision, impact and a safe reproduction outline once a private channel exists.

Never test against another person's data or account without explicit authorization.

No bounty or compensation is implied by a report.

There aren't any published security advisories