Skip to content

Security: HA-Update-Manager/.github

Security

.github/SECURITY.md

Security Policy

Reporting a Vulnerability

If you find a security vulnerability in one of these projects, please report it privately using GitHub's own private vulnerability reporting: open the affected repository's Security tab and select "Report a vulnerability." That keeps the report private between you and the maintainer until a fix is out.

Please don't open a public issue for a security report.

Supported Versions

Only the latest released version of a project receives security fixes. If a report affects an older version, please confirm the issue still reproduces on the latest release first.

What to Expect

This is a set of small, actively maintained hobby projects with a single maintainer, not a company with a dedicated security team. Reports are read and triaged as soon as reasonably possible, but there's no guaranteed response time. A fix, once confirmed, is released as its own patch version with a note in the affected project's release notes (without disclosing exploit details until users have had a reasonable chance to update).

There aren't any published security advisories