Skip to content

Security: jlcodes99/cockpit-tools

Security

SECURITY.md

Security Policy

Supported versions

This repository does not currently publish a supported-version matrix for security fixes. Please include the exact Cockpit Tools version and operating system in a report. If the issue also affects other releases, include the versions you have confirmed rather than assuming an upgrade fixes it.

Reporting a vulnerability

Do not put vulnerability details, working exploits, or credentials in a public issue, pull request, or discussion.

Open this repository's Security tab. If Report a vulnerability is available, use it to submit a private report. If private reporting is unavailable and no private contact has been published, open an issue that only asks the maintainer for a private reporting channel. Do not include the vulnerability or its reproduction steps in that issue.

In the private report, include the affected version/platform, expected and actual behavior, impact, and the smallest safe reproduction. Use dummy accounts and redacted examples. Never send live OAuth tokens, API keys, cookies, MFA secrets, account exports, or complete authentication files. Logs and screenshots can also contain these values; review them before sharing.

Coordinate any public disclosure with the maintainer. This policy does not promise a response deadline, fix date, or backport policy. Ordinary bugs that do not expose sensitive data or cross a security boundary can use the public issue tracker.

There aren't any published security advisories