Skip to content

Security: Bangkahdev/Atha

Security

SECURITY.md

Security Policy

Supported Versions

The following table outlines the supported versions for security updates and patches:

Version Supported
3.x
< 3.0

Reporting a Vulnerability

We take the security of atha seriously. If you discover a security vulnerability, please report it responsibly through our private reporting channels. Do not disclose security vulnerabilities publicly until they have been addressed and a patch has been released.

Private Disclosure

  • Please report vulnerabilities via GitHub Security Advisories by navigating to the Security tab of this repository and clicking Report a vulnerability.
  • Alternatively, you can reach out directly via email to the repository maintainer.

What to Include in Your Report

To help us triage and resolve the issue as quickly as possible, please include:

  • A detailed description of the vulnerability and its potential impact.
  • Step-by-step instructions or proof-of-concept (PoC) code to reproduce the issue safely.
  • Any relevant logs, configurations, or system details.

Our Response Process

  1. Acknowledgment: We will acknowledge receipt of your report within 48 hours.
  2. Investigation: We will investigate the issue, assess its severity, and coordinate a remediation plan.
  3. Patch & Release: Once a fix is verified, we will release an updated version and publish a security advisory acknowledging your contribution (if desired).

Thank you for helping keep atha secure for everyone.

There aren't any published security advisories