Skip to content

Security: centrys-labs/repolith

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Repolith, please report it responsibly.

Do not open a public GitHub issue.

Instead, use the Report a vulnerability button on the repository's Security Advisories page. GitHub private vulnerability reporting is enabled for this repository. Include:

  • A description of the vulnerability
  • Steps to reproduce
  • The potential impact
  • Any suggested fix (optional)

Reports are reviewed privately. Response and remediation times depend on the issue's severity and reproducibility.

Supported Versions

Version Supported
Latest main Yes
Older releases No

Disclosure Policy

We follow coordinated disclosure. Once a fix is released, we will:

  1. Credit the reporter (unless they prefer anonymity)
  2. Publish a brief advisory describing the issue and the fix

We ask that you give us reasonable time to address the issue before any public disclosure.

There aren't any published security advisories