Skip to content

Security: kill74/TeamPulseBridge

SECURITY.md

Security Policy

Supported Versions

Security fixes are provided for the latest release and the main branch.

Reporting a Vulnerability

Please do not open public issues for vulnerabilities.

  1. Open a private security advisory in GitHub Security tab.
  2. Include impact, reproduction steps, and suggested remediation.
  3. Expect an acknowledgment within 72 hours.

Disclosure Process

  • We validate and triage severity.
  • We prepare a fix and tests.
  • We publish release notes with mitigation guidance.

Scope

  • Webhook signature validation
  • Authz/authn middleware
  • Data handling and logging paths
  • CI/CD and supply chain integrity

There aren’t any published security advisories