Skip to content

Security: hidecard/zap

Security

SECURITY.md

Security Policy

Reporting Security Vulnerabilities

If you discover a security vulnerability in Zap, please report it responsibly:

  1. Do not open a public issue for security vulnerabilities
  2. Email security concerns to: security@zap-lang.dev (replace with actual contact)
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 7 days
  • Fix timeline: depends on severity
    • Critical: 1-2 weeks
    • High: 2-4 weeks
    • Medium: 1-2 months
    • Low: next scheduled release

Disclosure Policy

  • We follow coordinated disclosure
  • We will credit reporters (unless anonymity is requested)
  • We publish security advisories with each release

Supported Versions

Version Supported
2.x Yes
1.x No
< 1.0 No

Supported Release Lines

There aren't any published security advisories