At ResQ, we take security seriously. If you discover any security issues, we appreciate your cooperation in responsibly disclosing them to us.
To report a security vulnerability, please follow these steps:
-
Do not create a public GitHub issue. Security vulnerabilities should be reported privately.
-
Email us at [email protected] with a detailed description of the vulnerability. Include information such as:
- A clear and concise description of the vulnerability.
- Steps to reproduce the vulnerability.
- Any additional details that may help us understand and address the issue.
-
We will acknowledge your email within [48 hours] and work with you to understand and address the issue promptly.
Please note that this project is released with a Contributor Code of Conduct. By participating in this project, you agree to abide by its terms, including responsible and respectful disclosure of security vulnerabilities.
We encourage responsible disclosure of security vulnerabilities. When reporting vulnerabilities, please:
- Provide sufficient details for us to understand and reproduce the issue.
- Allow us a reasonable amount of time to address the issue before disclosing it publicly.
- Do not exploit the vulnerability for any reason.
This security policy covers only the official releases of ResQ. If you are using a fork or a modified version, please reach out to the maintainers of that project.
For security-related inquiries or to report a vulnerability, please contact us at [email protected].
Thank you for helping make ResQ a secure project for everyone!