Skip to content

Security: HannahVernon/pg-deploy

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release of pg-deploy is supported with security updates.

Version Supported
Latest release Yes
Older versions No

Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly:

  1. GitHub Private Vulnerability Reporting (preferred): Navigate to the repository's Security tab and click Report a vulnerability.

  2. Email: Send a detailed report to vuln@mvct.com.

Please include:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • The potential impact
  • Any suggested fixes or mitigations

Response Time

  • We will acknowledge your report within 48 hours.
  • We aim to provide a fix or mitigation plan within 7 days.

Disclosure

We follow a coordinated disclosure process. Once a fix is available, we will publish a security advisory and credit the reporter (unless anonymity is requested).

There aren't any published security advisories