Skip to content

Security: numfocus/project-funding-ledger

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

To report a suspected security vulnerability, contact the Project Funding Ledger maintainers privately at:

pfl_security@numfocus.org

Please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested remediation, if available

The maintainers will acknowledge the report and evaluate the issue as promptly as reasonably possible.

Please do not publicly disclose the vulnerability until the maintainers have had a reasonable opportunity to investigate and address it.

Supported Versions

The Project Funding Ledger is currently under development and has not yet issued a production release.

Security updates will generally apply to the latest version of the main development branch until a formal release and version-support policy is established.

There aren't any published security advisories