Please do not report security vulnerabilities through public GitHub issues.
If you discover a security vulnerability in altissimo-auth, please report it responsibly by emailing:
Please include:
- A description of the vulnerability
- Steps to reproduce the issue
- The potential impact
- Any suggested fixes (if applicable)
- Acknowledgment: Within 48 hours of receiving the report
- Assessment: Within 7 days, we will assess the vulnerability and determine the severity
- Fix: Critical vulnerabilities will be patched as soon as possible; high-severity issues within 30 days
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
This policy applies to the altissimo-auth package and its core modules. Third-party dependencies
(e.g., firebase-admin, google-auth) are not covered — please report those vulnerabilities
to the respective maintainers.