The Lupaxa Project maintains a single organisation-wide Security Policy to ensure security vulnerabilities are reported, assessed and handled responsibly across every repository and organisation.
The authoritative Security Policy is available here: The Lupaxa Project: Security Policy
It includes guidance on:
- Reporting security vulnerabilities responsibly.
- Information to include with security reports.
- Vulnerability assessment and disclosure procedures.
- Security response expectations and communication.
Unless explicitly stated otherwise, this Security Policy applies to every repository and organisation within The Lupaxa Project.
Repository-specific exceptions or additional guidance, where applicable, should be documented separately within the repository itself.