Skip to content

Security: Eyevinn/intercom-manager

Security

SECURITY.md

Security Policy

This policy applies to the open source projects published by Eyevinn Technology AB.

Reporting a Vulnerability

If you discover a security vulnerability in an Eyevinn project, please report it to us privately rather than opening a public issue.

Email: [email protected]

Include the repository name in the subject line, and as much of the following as you have:

  • a description of the vulnerability
  • steps to reproduce
  • the potential impact
  • a suggested fix, if you have one

What to expect

  • We acknowledge reports as promptly as we can, normally within one working day
  • We aim to give an initial assessment within a few working days
  • We keep you updated while the issue is open
  • We prioritise fixes by severity, and we will tell you if a fix is outside our control

How vulnerabilities are handled

Reports are triaged privately. A confirmed vulnerability is recorded, fixed in the affected repository, and the fix is published as a normal release of that project. Where a GitHub Security Advisory is appropriate, it is published on the repository so downstream users are notified through GitHub's own channels. Disclosure is coordinated: we publish after a fix is available, and we credit the reporter if they wish to be credited.

Dependencies

We monitor dependencies for known vulnerabilities using GitHub security advisories, Dependabot alerts and the package managers' own audit tooling.

Non-security issues

For ordinary bugs and feature requests, please use the GitHub issue tracker of the repository concerned.

Thank you for helping keep Eyevinn's open source projects secure.

There aren't any published security advisories