Skip to content

Security: Stackbilt-dev/cc-taskrunner

Security

SECURITY.md

Security

For the full Stackbilt security policy, see https://docs.stackbilt.dev/security/.

Reporting a Vulnerability

Do not open a public GitHub issue for security vulnerabilities.

How to report

Response targets

SeverityAcknowledgementFix target
Critical — active exploitation, data exposure24 hours7 days
High — exploitable with effort48 hours14 days
Medium / Low5 business daysNext release cycle

These are targets, not contractual SLAs. Stackbilt is a solo-founder operation and response times reflect that reality honestly. Critical issues affecting user data are prioritized above everything else.

Scope

This policy covers all software published in this repository. For the full policy covering the entire Stackbilt-dev organization, see the canonical security policy.

Out of scope

  • Denial of service against free-tier services (Cloudflare handles DDoS)
  • Rate limiting bypass on non-authenticated endpoints (unless it enables data access)
  • Missing security headers on non-production deployments
  • Vulnerabilities in third-party dependencies where this repo is not the upstream maintainer

Disclosure

  • Stackbilt practices coordinated disclosure with a minimum 90-day window (30 days for critical).
  • Reporters are credited in release notes unless anonymity is requested.
  • Good-faith security research within this policy will not face legal action.

Contact

There aren't any published security advisories