Skip to content

Security: shellOrg/bip32utils

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Do not report suspected vulnerabilities through public issues, pull requests, discussions, or social media.

Use this repository's Security → Report a vulnerability form. Include the affected version, impact, prerequisites, reproduction steps, and suggested remediation. Remove real credentials and personal data from evidence.

Maintainers aim to acknowledge a report within three business days, provide an initial assessment within seven business days, and coordinate remediation and disclosure with the reporter. Timelines may vary with severity and complexity.

Supported versions

Security fixes are provided for the latest released version and the default branch unless the project documentation states otherwise.

Disclosure

Please allow maintainers reasonable time to investigate and release a fix before public disclosure. Maintainers will credit reporters who want attribution, subject to coordinated disclosure and legal constraints.

There aren't any published security advisories