We release patches for security vulnerabilities for the following versions:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
We take security vulnerabilities seriously. If you discover a security vulnerability, please report it responsibly.
Do not open a public GitHub issue. Instead, please report security vulnerabilities to:
Email: security@sanityops.org
Please include the following information:
- Description of the vulnerability
- Steps to reproduce the issue
- Affected versions
- Potential impact
- Suggested fix (if any)
| Stage | Timeline |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial Assessment | Within 7 days |
| Fix Development | Depends on severity |
| Release | As soon as possible |
We follow a coordinated disclosure process:
- We will acknowledge your report within 48 hours
- We will provide an initial assessment within 7 days
- We will work on a fix and prepare a release
- We will notify you before public disclosure
- We will credit you in the release notes (if desired)
We support responsible security research. We will not pursue legal action against individuals who:
- Report security vulnerabilities in good faith
- Avoid accessing, modifying, or deleting data that is not theirs
- Do not disrupt our services or users
- Provide us reasonable time to fix the issue before public disclosure
Thank you for helping keep Sanityops CLI and its users safe!