CVP takes the security of our open-source projects seriously. Thank you for helping us keep them safe.
Please do not report security vulnerabilities through public GitHub issues.
Instead, use one of these channels:
- GitHub private vulnerability reporting (preferred): on the affected repository, go to the Security tab and click Report a vulnerability. This opens a private advisory visible only to you and our maintainers.
- Email: info@cvpcorp.com with the subject line
SECURITY: <repository name>.
Include as much of the following as you can:
- The repository and version/commit affected
- A description of the issue and its potential impact
- Steps to reproduce (proof-of-concept code is welcome)
- We aim to acknowledge reports within 5 business days.
- We'll keep you informed as we triage, develop, and release a fix.
- With your permission, we're glad to credit you in the advisory once the issue is resolved.
This policy covers the open-source repositories in the cvpcorp organization. For security concerns about cvpcorp.com or CVP products such as Fifer, please contact us through cvpcorp.com instead.