Skip to content

Security: CTRLRun/.github

Security

SECURITY.md

Security Policy

This is the organisation-wide fallback. A repository that ships its own SECURITY.md overrides it — see ctrlrun's policy for the release provenance, attestation and signing details specific to that project.

Reporting a vulnerability

Report vulnerabilities privately to contact@arpanghoshal.com. Please do not open a public issue for a security report.

Include what you need to make the problem reproducible: the version, the policy file, and the sequence of actions. A failing test is the fastest possible report.

Expect an acknowledgement within 72 hours and an assessment within seven days. If a fix is warranted you will be credited in the release notes unless you ask not to be.

Scope

We are most interested in anything that lets a consequential action happen more than once, happen differently from how it was approved, or happen without leaving a receipt — and in anything that turns an outcome the code cannot observe into a definite one.

There aren't any published security advisories