Skip to content

Security: Pact-Community-Organization/.github

Security

SECURITY.md

Security Policy

The Pact Community Organization takes the security of our software seriously. Thank you for helping keep our users safe by disclosing vulnerabilities responsibly.

This is the organization-wide default policy. A repository may publish its own SECURITY.md, which takes precedence for that repository.

Reporting a Vulnerability

Do not report security vulnerabilities through public GitHub issues, Discussions, or pull requests.

Instead, report them privately through a GitHub Security Advisory:

  1. Go to the affected repository's Security tab.
  2. Click Report a vulnerability (Private vulnerability reporting).
  3. Or email info@pact-community.org with the details below.

Please include:

  • Type of issue (e.g. prompt injection, privilege escalation, data exfiltration, supply-chain, path traversal, command injection).
  • Affected repository, component, and version or commit.
  • Step-by-step reproduction or proof of concept (only if safe to share).
  • Impact assessment (what an attacker could achieve).
  • Any suggested mitigation.

Our Commitment

  • We will acknowledge your report within 3 business days (best effort).
  • We will provide an assessment and expected timeline after triage.
  • We will keep you informed as we work on a fix.
  • We will credit you in the advisory unless you prefer to remain anonymous.

Safe Harbor

We support good-faith security research. If you make a good-faith effort to comply with this policy, we will consider your research authorized, work with you to understand and resolve the issue quickly, and will not pursue or support legal action against you.

There aren't any published security advisories