36 lines
1.4 KiB
Markdown
36 lines
1.4 KiB
Markdown
# Security Policy
|
|
|
|
## Reporting a vulnerability
|
|
|
|
Email **security@soulcraft.com**. That's the one door for security reports
|
|
across the company, and it works the same way for Brainy: every report is
|
|
read by a human, you'll get a private receipt, and we'll work with you on
|
|
coordinated disclosure — please don't open a public issue for anything
|
|
that isn't already public.
|
|
|
|
Include what you'd want if you were on the other end: affected version,
|
|
how to reproduce, and what you think the impact is. If you have a patch or
|
|
a suggested fix, send it along — it's welcome but not required.
|
|
|
|
There is no bounty program today. We're saying that plainly so you know
|
|
what to expect going in.
|
|
|
|
## Response time
|
|
|
|
We respond as fast as truth allows. That means: no fixed SLA, no promise of
|
|
a reply within a specific number of hours — but a real report from a real
|
|
person gets read promptly and taken seriously. If you haven't heard anything
|
|
in a reasonable stretch, a follow-up email is completely fine.
|
|
|
|
## Supported versions
|
|
|
|
The latest `8.x` minor release line receives security fixes. If you're
|
|
running an older major version, please upgrade before reporting — we can't
|
|
commit to backporting fixes to unsupported lines.
|
|
|
|
## Scope
|
|
|
|
This policy covers the `@soulcraft/brainy` package itself — the code in
|
|
this repository. If you're evaluating a deployment that also uses
|
|
`@soulcraft/cor`, report issues in that package the same way, to the same
|
|
address; we'll route internally.
|