Skip to content

Security: Skunkworks-Digital/www

SECURITY.md

πŸ” Security Policy

Skunkworks Digital is committed to protecting the integrity and security of our codebase and the applications we build.


πŸ“¦ Supported Versions

Version Status
5.1.x βœ… Supported
5.0.x ❌ No longer supported
4.0.x βœ… Supported
< 4.0 ❌ Deprecated

🚨 Reporting a Vulnerability

We welcome responsible disclosure of security vulnerabilities. If you discover a security issue in this repository or any of our digital assets, please follow these steps:

πŸ” Reporting Process

  1. Send a detailed report to:
    πŸ“§ security@skunkworks.digital

  2. Include the following in your report:

    • Project name and affected file/endpoint
    • Version (if applicable)
    • Steps to reproduce the issue
    • Proof-of-concept (PoC) code or screenshots
    • Potential impact and suggested remediation (if available)
  3. Response Time:

    • ⏱️ Acknowledgement within 48 hours
    • πŸ” Investigation and triage within 7 business days
    • πŸ› οΈ Patch ETA will be communicated based on severity
  4. Disclosure:

    • Please do not disclose the vulnerability publicly before a fix is released.
    • We will credit responsible reporters in our release notes unless anonymity is requested.

βœ… Commitment

We follow industry best practices, including:

  • Regular dependency audits
  • Static and dynamic code analysis
  • GitHub Code Scanning & Dependabot alerts
  • 2FA and role-based access control (RBAC)

πŸ” GPG Signed Commits

We require all maintainers to use GPG-signed commits for enhanced trust.


πŸ™ Thank You

Your help in making Skunkworks Digital safer is highly appreciated.

There aren't any published security advisories