Skip to content

Security: altissimo-hq/auth-providers-python

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you discover a security vulnerability in altissimo-auth, please report it responsibly by emailing:

📧 security@altissimo.dev

Please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested fixes (if applicable)

Response Timeline

  • Acknowledgment: Within 48 hours of receiving the report
  • Assessment: Within 7 days, we will assess the vulnerability and determine the severity
  • Fix: Critical vulnerabilities will be patched as soon as possible; high-severity issues within 30 days

Supported Versions

Version Supported
0.1.x

Scope

This policy applies to the altissimo-auth package and its core modules. Third-party dependencies (e.g., firebase-admin, google-auth) are not covered — please report those vulnerabilities to the respective maintainers.

There aren't any published security advisories