Skip to content

Security: EmadHelmi/codex-python-boilerplate

SECURITY.md

Security Policy

Supported Versions

This repository is a reusable project baseline rather than a deployed application. Security fixes are applied to the current default branch.

Target Supported
Current main branch Yes
Older commits or unmaintained tags No
Projects created from this template Maintained by their respective owners

Derived projects must define and operate their own security policy. A fix in this boilerplate is not automatically propagated to repositories created from it.

Reporting a Vulnerability

Do not open a public issue for a suspected vulnerability.

Use GitHub's private vulnerability reporting as the preferred reporting channel. If that channel is unavailable, send a private report to s.emad.helmi@gmail.com with a subject beginning with [SECURITY].

Include, when available:

  • the affected file, component, or workflow;
  • the impact and realistic attack scenario;
  • steps or a minimal proof of concept;
  • affected versions or commits;
  • a proposed mitigation;
  • whether the issue has been disclosed elsewhere.

Do not include real credentials, personal data, or third-party secrets in the report.

Response and Disclosure

The maintainer aims to acknowledge a report within seven calendar days and provide an initial status within fourteen calendar days. These targets are not a guaranteed service-level agreement.

Please allow reasonable time for investigation and remediation before public disclosure. When a report is accepted, disclosure and credit will be coordinated with the reporter unless safety, privacy, or legal constraints require another approach.

Reports that concern a derived project should be sent to that project's maintainer unless the underlying issue is present in this boilerplate.

There aren't any published security advisories