Skip to content

Security: perishdev/.github

Security

SECURITY.md

Security Policy

Thanks for helping make @perishdev projects safe for everyone. 🔒

This policy applies to every repository in the perishdev organization that does not define its own SECURITY.md.

Supported Versions

The latest released version of each project is supported. You are encouraged to keep your dependencies current so that you benefit from the latest features, bug fixes, and security fixes.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, use GitHub's private vulnerability reporting:

  1. Browse to the affected repository.
  2. Open the Security tab → AdvisoriesReport a vulnerability.

To help us triage your report quickly, please include as much of the following as you can:

  • The type of issue (e.g. buffer overflow, SQL injection, cross-site scripting).
  • Full paths of the source file(s) related to the issue.
  • The location of the affected source code (tag/branch/commit or direct URL).
  • Any special configuration required to reproduce the issue.
  • Step-by-step instructions to reproduce the issue.
  • Proof-of-concept or exploit code, if possible.
  • The impact of the issue, including how an attacker might exploit it.

We will acknowledge your report, keep you informed of progress, and credit you in the advisory once a fix is released (unless you prefer to remain anonymous).

A Note on AI-Assisted Reports

If you used an AI-assisted or otherwise automated tool to find the issue, a human must verify that the vulnerability is real and reproducible before you report it, and you must disclose the use of those tools.

Do not submit reports that were automatically generated without human review. Low-quality, machine-generated reports create significant overhead for maintainers and are almost always meaningless — we will treat them as spam, close them, and may block the reporter.

Public Disclosure

Please refrain from publicly discussing a potential vulnerability until a fix is available. Coordinated, private disclosure limits the potential impact on users.


Thanks for your help keeping the community secure!

There aren't any published security advisories