Skip to content

Security: Dev9269/zero-trust-lab

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Zero Trust Lab, do not open a public GitHub issue. Report it privately.

Report via GitHub Security Advisory:

  1. Go to the repository's Security tab
  2. Click Report a vulnerability (or use https://github.com/Dev9269/zero-trust-lab/security/advisories/new)
  3. Fill in the details

Or email directly: jainammaru567000@gmail.com GPG fingerprint: 00D6CCEA36D10407

Please include:

  • Type of vulnerability
  • Steps to reproduce (PoC preferred)
  • Affected versions
  • Potential impact
  • Any suggested fix (optional)

Response Timeline

Step Timeframe
Acknowledgment Within 48 hours
Initial assessment Within 5 business days
Fix timeline Communicated based on severity
Coordinated disclosure 90 days after fix shipped

Supported Versions

Version Supported
latest
older

Scope

This policy covers the gateway, authorization bridge, SSH setup, and deployment configurations in this repository. This is a lab/learning environment — do not deploy untrusted configurations to production.

Coordinated Disclosure

We follow coordinated disclosure. Please allow us reasonable time to fix the issue before any public disclosure. We will credit reporters in release notes (with permission).

There aren't any published security advisories