This is the org-wide default. It applies to any Entire VC repository that does not have its own
SECURITY.md.
Do NOT create a public GitHub issue for security vulnerabilities.
Use this repository's Security tab → Report a vulnerability (GitHub private
vulnerability reporting), if enabled. If you cannot use GitHub, email support@entire.vc with
SECURITY in the subject and we will move the conversation somewhere private; do not put
vulnerability details in a public issue in the meantime.
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment — We'll respond within 48 hours
- Assessment — We'll investigate and assess severity
- Fix — We'll develop and test a fix
- Disclosure — We'll coordinate disclosure timing with you
- Credit — We'll credit you in the release notes (if desired)
Thank you for helping keep Entire VC's projects secure!