Skip to content

Security: mBlomsterberg/terraform-beginners-guide

Security

SECURITY.md

Security Policy

(notes: this is an inspirational Security Policy)

Supported Versions

We are committed to maintaining the security of our software. To ensure efficient use of resources and provide the most secure experience, we only support the latest version of our software with security updates.

Version Supported
Latest
Older

Please make sure to update to the latest version to benefit from the latest security fixes and improvements.

Reporting a Vulnerability

We take the security of our project seriously. If you have discovered a security vulnerability, we appreciate your help in disclosing it to us in a responsible manner.

Please follow the steps below to report a security issue.

  1. Email Us: Send a message to mBlomsterberg. If you prefer to remain anonymous, consider using a temporary email service.
  2. Provide Details: Include as much information as possible about the potential vulnerability so we can reproduce it. This might include:
    • The version of the software that contains the vulnerability.
    • A description of the type of vulnerability, such as SQL injection, buffer overflow, etc.
    • Steps to reproduce the vulnerability.
  3. Wait for Initial Response: We aim to respond to all vulnerability reports within 48 hours. Once we have assessed the report, we will contact you to discuss the implications and plan a fix.
  4. Disclosure: Please do not disclose the issue to the public until we've had a chance to address it. We will work with you to determine the most appropriate time to release a public advisory.

Security Update Policy

When a security issue is discovered, we will address it as follows:

  • Patch Release: Vulnerabilities will be patched in the next patch release of the software.
  • Hotfixes: Critical vulnerabilities will receive immediate attention and may result in a hotfix release outside of the normal release schedule.

We appreciate your help in keeping our project and its users safe.

There aren’t any published security advisories