Skip to content

Security: lastobelus/markover

SECURITY.md

Security Policy

Supported versions

Markover is in 0.x preview. Only the latest published release receives security fixes; older releases are unsupported.

Version Supported
Latest published release Yes
Older releases No

Report a vulnerability privately

Do not open a public issue or Discussion for a suspected vulnerability. Use GitHub private vulnerability reporting and include only the information needed to investigate:

  • the affected Markover version or development commit;
  • the affected component and expected impact;
  • reproducible steps or a minimal proof of concept;
  • any known mitigations; and
  • whether you would like public credit.

Remove credentials, private review content, identifying local paths, and other unrelated sensitive data before submitting a report.

What to expect

The maintainer will make a best-effort acknowledgement within 14 calendar days. There is no fixed remediation deadline; timing depends on severity, complexity, and release risk.

Please keep an unresolved vulnerability confidential until a fix or mitigation is available and a disclosure date has been coordinated. Material confirmed vulnerabilities will normally be published through a GitHub Security Advisory. Low-risk hardening may instead be described in ordinary release notes. Public credit is given only with the reporter's explicit consent.

Good-faith research

Markover will not pursue legal action against good-faith security research that follows this policy, avoids privacy violations and unnecessary data access, does not disrupt other people or services, does not use extortion, and allows a reasonable opportunity to investigate and remediate the report.

This safe harbor applies only to activity involving Markover-controlled code and services. It does not authorize testing third-party systems or data.

There aren't any published security advisories