Default security policy for beardwhocodes
projects. A repository may override it with its own SECURITY.md.
Please report security issues privately — do not open a public issue, pull request, or discussion.
- Preferred: open a private report via the affected repository's Security tab → "Report a vulnerability" (GitHub Security Advisories).
- Email: hello@beardwho.codes
Please include enough to reproduce: affected repository + version/commit, impact, and a proof-of-concept or steps where possible.
Good-faith targets for a small, best-effort maintainer (not a contractual SLA):
- Acknowledgement: within 3 business days.
- Assessment: within 7 business days.
- Fix / mitigation: prioritized by severity once confirmed.
We'll credit you in the disclosure unless you prefer to remain anonymous. Please allow reasonable time for a fix before any public disclosure (coordinated disclosure).