Skip to content

Security: CVPcorp/.github

SECURITY.md

Security Policy

CVP takes the security of our open-source projects seriously. Thank you for helping us keep them safe.

Reporting a vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, use one of these channels:

  1. GitHub private vulnerability reporting (preferred): on the affected repository, go to the Security tab and click Report a vulnerability. This opens a private advisory visible only to you and our maintainers.
  2. Email: info@cvpcorp.com with the subject line SECURITY: <repository name>.

Include as much of the following as you can:

  • The repository and version/commit affected
  • A description of the issue and its potential impact
  • Steps to reproduce (proof-of-concept code is welcome)

What to expect

  • We aim to acknowledge reports within 5 business days.
  • We'll keep you informed as we triage, develop, and release a fix.
  • With your permission, we're glad to credit you in the advisory once the issue is resolved.

Scope

This policy covers the open-source repositories in the cvpcorp organization. For security concerns about cvpcorp.com or CVP products such as Fifer, please contact us through cvpcorp.com instead.

There aren't any published security advisories