Skip to content

Security: HailBytes/sbom-diff

Security

SECURITY.md

Security Policy

@hailbytes/sbom-diff is a supply-chain security tool, so we hold its own supply chain to the same standard. This document explains which versions we support and how to report a vulnerability.

Supported Versions

Security fixes are released for the latest published 1.x version. Please upgrade to the newest release before reporting an issue.

Version Supported
1.x
< 1.0

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussions.

Instead, use GitHub's private vulnerability reporting:

  1. Go to the repository's Security tab.
  2. Click Report a vulnerability (Private vulnerability reporting).
  3. Provide as much detail as you can — see below.

If you are unable to use private reporting, email security@hailbytes.com with the details.

What to include

  • A description of the vulnerability and its impact.
  • Steps to reproduce (a minimal SBOM input or command line is ideal).
  • The affected version(s) and platform.
  • Any known workarounds or suggested fixes.

Our commitment

  • We will acknowledge your report within 3 business days.
  • We will provide an assessment and expected timeline within 10 business days.
  • We will keep you informed as we work on a fix and coordinate disclosure.
  • With your permission, we will credit you once the fix is released.

Thank you for helping keep @hailbytes/sbom-diff and its users secure.

There aren't any published security advisories