Skip to content

Security: bmlt-enabled/yap

SECURITY.md

Security Policy

Reporting a Vulnerability

The yap maintainers take security seriously. If you believe you have found a security vulnerability in yap, please report it to us privately. Do not open a public GitHub issue, pull request, or discussion for a security problem.

Please use GitHub's private vulnerability reporting:

  1. Go to the Security tab of this repository.
  2. Click Report a vulnerability to open a private security advisory that is visible only to the maintainers.

To help us triage the report quickly, please include as much of the following as you can:

  • A description of the vulnerability and its potential impact.
  • The version or branch affected (see Supported Versions).
  • Steps to reproduce, or a proof of concept.
  • Any suggested remediation, if you have one.

Supported Versions

Security fixes are provided for the following release lines:

Version Supported
5.0.x (development)
4.5.x
< 4.5

We recommend running the latest release.

Response Process

  • We will acknowledge your report within 5 business days.
  • We will work with you to understand and validate the issue.
  • We aim to provide a resolution or mitigation plan within 30 days, depending on the severity and complexity of the issue.
  • We follow a coordinated-disclosure process: please give us reasonable time to release a fix before any public disclosure. Once a fix is available, we will publish a GitHub Security Advisory.

Credit

We are happy to credit reporters in the published advisory. Let us know in your report whether you would like to be credited, and how you would like to be named.

There aren't any published security advisories