Skip to content

Security: helpwave/tasks

Security

SECURITY.md

Security Policy

Pre-release software.helpwave/tasks is under active development and is not yet released for productive use. It has not completed a full security review, and no deployment should be treated as production-ready yet. This is expected to change over the coming month.

Reporting a vulnerability

Please report security issues privately — do not open a public GitHub issue or pull request for a suspected vulnerability.

Follow helpwave's central vulnerability disclosure policy: https://helpwave.de/.well-known/security.txt

When reporting, please include:

  • affected component and version/commit,
  • a description of the issue and its impact,
  • reproduction steps or a proof of concept,
  • any suggested remediation.

How reports are resolved

  1. We acknowledge your report by email.
  2. We triage and confirm the issue, and agree a coordinated disclosure timeline with you.
  3. We develop and validate a fix on a private branch, then merge and release it.
  4. We credit reporters who wish to be acknowledged once a fix is available.

A machine-readable copy of these contact details is served from .well-known/security.txt.

There aren't any published security advisories