Thanks for helping make @perishdev projects safe for everyone. 🔒
This policy applies to every repository in the perishdev organization that does not define its own SECURITY.md.
The latest released version of each project is supported. You are encouraged to keep your dependencies current so that you benefit from the latest features, bug fixes, and security fixes.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use GitHub's private vulnerability reporting:
- Browse to the affected repository.
- Open the Security tab → Advisories → Report a vulnerability.
To help us triage your report quickly, please include as much of the following as you can:
- The type of issue (e.g. buffer overflow, SQL injection, cross-site scripting).
- Full paths of the source file(s) related to the issue.
- The location of the affected source code (tag/branch/commit or direct URL).
- Any special configuration required to reproduce the issue.
- Step-by-step instructions to reproduce the issue.
- Proof-of-concept or exploit code, if possible.
- The impact of the issue, including how an attacker might exploit it.
We will acknowledge your report, keep you informed of progress, and credit you in the advisory once a fix is released (unless you prefer to remain anonymous).
If you used an AI-assisted or otherwise automated tool to find the issue, a human must verify that the vulnerability is real and reproducible before you report it, and you must disclose the use of those tools.
Do not submit reports that were automatically generated without human review. Low-quality, machine-generated reports create significant overhead for maintainers and are almost always meaningless — we will treat them as spam, close them, and may block the reporter.
Please refrain from publicly discussing a potential vulnerability until a fix is available. Coordinated, private disclosure limits the potential impact on users.
Thanks for your help keeping the community secure!