Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use GitHub's private vulnerability reporting on the affected repository:
- Navigate to the repository's Security tab.
- Select Report a vulnerability.
- Provide as much detail as you can — affected versions, reproduction steps, and potential impact.
If private vulnerability reporting is not enabled on a particular repository, open a report on this repository (NorseArchitecture/.github) instead and name the affected project in the description.
- Acknowledgment of your report within 5 business days.
- An assessment of the issue and, if confirmed, a remediation plan with an estimated timeline.
- Credit in the release notes or security advisory, unless you prefer to remain anonymous.
We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure.
Unless a repository states otherwise in its own SECURITY.md, security fixes are applied to the latest released version of each project.
This policy covers all repositories in the Norse Architecture organization. Vulnerabilities in third-party dependencies should be reported to the upstream project; we will track and adopt upstream fixes as they become available.