Skip to content

Security: 0xCardinal/actsense

.github/SECURITY.md

Security Policy

Supported Versions

We actively support and provide security updates for the following versions:

Version Supported
Latest ✅
< Latest ❌

Reporting a Vulnerability

We take security vulnerabilities seriously. If you discover a security vulnerability, please follow these steps:

  1. Do NOT create a public GitHub issue
  2. Email security details to: [Your Security Email] (or create a private security advisory)
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if available)

Security Best Practices

This project follows security best practices:

  • ✅ Regular dependency updates via Dependabot
  • ✅ Automated security scanning (CodeQL, npm audit, pip-audit)
  • ✅ CI/CD pipeline with security checks
  • ✅ Pinned dependencies where possible
  • ✅ Regular security audits

Disclosure Policy

  • We will acknowledge receipt of your report within 48 hours
  • We will provide an initial assessment within 7 days
  • We will keep you informed of our progress
  • We will notify you when the vulnerability is fixed
  • We will credit you in the security advisory (if desired)

Security Updates

Security updates are released as soon as possible after a vulnerability is confirmed and fixed. Critical vulnerabilities may result in immediate patch releases.

There aren't any published security advisories