Security Policy
We appreciate responsible disclosure of security vulnerabilities. Please follow the guidance below so we can investigate and resolve issues quickly.
Reporting a Vulnerability
Use our dedicated security contact and do not file a public issue:
- Email: security@nanores.org
When reporting, please include:
- A clear description of the issue and potential impact
- Steps to reproduce (proof of concept if available)
- Affected pages, files, or URLs
- Any relevant logs, screenshots, or configuration details
Disclosure Expectations
- Please keep the report private until we confirm a fix or provide guidance.
- We will coordinate a disclosure timeline with you if the issue is confirmed.
- We may request additional details to validate or reproduce the report.
Response Timelines
We aim to:
- Acknowledge receipt within 3 business days
- Triage and provide an initial assessment within 7 business days
- Remediate confirmed issues within 30 business days, or provide a status update and revised timeline
Scope
This policy covers:
- Documentation content in this repository
- Published documentation at https://docs.nanores.org (or its current public domain)
Out of scope (unless it directly affects this repository) includes:
- Third-party services and infrastructure not controlled by this project
- Social engineering or physical security issues
Thank you for helping keep the project and community safe.