Skip to content

Security: davep/rogallo

SECURITY.md

Security Policy

Thanks for helping keep Rogallo safe.

Supported Versions

Rogallo is a solo-maintained project, so security fixes are handled on a best-effort basis.

Please report issues against the latest code on the main branch.

Reporting a Vulnerability

If you think you found a security issue, please do not open a public issue.

Please report it privately through GitHub’s private vulnerability reporting

Please include:

  • What you found
  • How to reproduce it
  • What version/commit you tested
  • Any idea of impact

What to Expect

I’ll do my best to:

  • Acknowledge your report within a couple or so days
  • Confirm whether it’s a real vulnerability
  • Fix it and publish a patch when possible
  • Credit you publicly (if you want)

Because this is a spare-time project, response/fix times will vary.

Scope Notes

Useful reports usually involve things like:

  • Command execution/injection risks
  • Unsafe handling of remote/untrusted content
  • Accidental credential or token exposure
  • Dependency issues with real-world impact

There aren't any published security advisories