Skip to content

Security: Indrooneel/mig-core

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

MIG Core is an execution control engine for critical infrastructure. We take security seriously.

If you discover a security vulnerability in MIG Core, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, email: neel@houseofgalatine.com

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

You will receive a response within 48 hours.

Scope

This policy covers the MIG Core codebase in this repository. It does not cover:

  • The MIG Playground (client-side demo at houseofgalatine.com/playground)
  • The production MIG engine (proprietary, not in this repo)
  • Third-party dependencies

Responsible Disclosure

We ask that you:

  • Give us reasonable time to fix the issue before public disclosure
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it
  • Do not access or modify other users' data

Recognition

Security researchers who report valid vulnerabilities will be credited in our changelog (with permission).

Contact

Security: neel@houseofgalatine.com Website: houseofgalatine.com

There aren't any published security advisories