Skip to content

Security: mojoatomic/atomic-deployments

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x

Reporting a Vulnerability

Do not open a public issue for security vulnerabilities.

Report privately via GitHub Security Advisories.

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Initial response: 48 hours
  • Status update: 7 days
  • Resolution target: 30 days (depending on complexity)

What to Expect

  1. Acknowledgment of your report
  2. Assessment and reproduction
  3. Fix development
  4. Coordinated disclosure (you'll be credited unless you prefer anonymity)

Scope

This policy covers:

  • The deploy.sh script
  • Any officially published releases

Out of scope:

  • Third-party forks
  • Modifications you've made locally

There aren’t any published security advisories