Skip to content

Security: tuzuminami/local-workflow-core

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.x Yes

Reporting a Vulnerability

Use private channels only.

Do not disclose vulnerability details in public issues, discussions, pull requests, or commits.

Preferred Channel: GitHub Private Vulnerability Reporting

Use GitHub private advisory reporting first:

  1. Open the repository Security tab.
  2. Select Report a vulnerability.
  3. Submit a private advisory with the details listed below.

Direct URL: https://github.com/project01/local-workflow-core/security/advisories/new

Fallback Channel: Security Response Mailbox

If GitHub private advisory submission is unavailable, email: security@local-workflow-core.dev

Use [SECURITY][CONFIDENTIAL] in the subject line. Share a minimal reproduction first; for sensitive exploit artifacts, wait for encrypted channel instructions in our reply.

Include in the Report

  • affected version(s) and environment
  • reproduction steps or proof-of-concept
  • impact and exploitability estimate
  • proposed mitigation or workaround, if known

Response Targets

  • Acknowledgement: within 2 business days.
  • Triage decision: within 5 business days.
  • Fix plan for High/Critical: within 7 calendar days.

Disclosure

Do not open public issues for unpatched vulnerabilities. We publish coordinated advisories after fix release.

There aren't any published security advisories