Skip to content

Security: ScalePivot/.github

SECURITY.md

Security Policy

JUNSHU Security treats vulnerability reports as technical collaboration. Please report suspected security issues privately and allow reasonable time for investigation before public disclosure.

Current Support Status

The open-source ecosystem is at a foundation stage and has no production release currently declared as supported. Each future project will publish its own supported versions and security boundaries. A repository-specific policy takes precedence over this shared policy.

Reporting a Vulnerability

Do not create a public issue, discussion, pull request, or social-media post for a suspected vulnerability.

Use the affected repository's Security tab and select Report a vulnerability. If the affected repository is not public yet, or no repository-specific channel is available, submit a private security advisory in this repository.

Include, when available:

  • affected repository, component, version, commit, or deployment mode;
  • concise impact and realistic attack scenario;
  • prerequisites, trust boundaries, and required permissions;
  • reproducible steps or a minimal proof of concept;
  • relevant logs with credentials and personal data removed;
  • suggested mitigation or containment options;
  • whether the issue has been disclosed elsewhere.

Do not send live credentials, customer data, private keys, production tokens, or unnecessary personal information. Use synthetic test data and redact sensitive values.

What to Expect

Maintainers will aim to:

  1. acknowledge receipt and establish a private channel;
  2. validate impact, scope, and affected versions;
  3. coordinate remediation and verification;
  4. discuss disclosure timing and credit with the reporter;
  5. publish an advisory when doing so helps users act safely.

No fixed response or remediation deadline is promised at this stage. Status will be communicated through the private advisory whenever possible.

Responsible Research and Safe Harbor

Good-faith research should avoid privacy violations, service degradation, persistence, lateral movement, social engineering, and access beyond what is necessary to demonstrate impact. Stop testing and report immediately if you encounter sensitive data or affect other users.

JUNSHU Security will not recommend legal action for good-faith research that follows this policy, respects applicable law, avoids harm, and provides a reasonable opportunity to remediate. This statement does not authorize testing of third-party systems or override their policies.

There aren't any published security advisories