Skip to content

Security: dylan-smith/CheckMate2

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in CheckMate, please report it responsibly.

Do not open a public GitHub issue for security vulnerabilities.

Instead, please use GitHub's private vulnerability reporting feature on this repository.

What to Include

  • A description of the vulnerability.
  • Steps to reproduce the issue.
  • The potential impact.
  • Any suggested fixes (if applicable).

What to Expect

  • An acknowledgment of your report within 7 days.
  • An assessment and planned fix timeline.
  • Credit in the fix (unless you prefer to remain anonymous).

Supported Versions

Security updates are applied to the latest version of the project on the main branch.

Best Practices

  • Keep dependencies up to date.
  • Never commit secrets, credentials, or API keys to the repository.
  • Use environment variables or secure configuration for sensitive values.

There aren't any published security advisories