This vulnerability disclosure process describes how we accept and respond to security vulnerabilities from both developers and others. Our process follows 4 steps: Report, Investigate, Remediate, and Disclose.
Reporters should email security@debthelper.com or open a GitHub Security Vulnerability Report with:
- A description of the problem.
- Steps we can follow to reproduce the problem.
- Affected versions.
- If known, mitigations for the problem.
We will respond within 3 days of the reporter's submission to acknowledge receipt of their report. Here is a template acknowledgement message:
Hi $REPORTER,
Thank you for reporting this problem to us. We are currently investigating and will reach out sometime in the next 3 days.
Best,
The Debt Intelligence System Team
We will investigate the issue to determine if it is a vulnerability and if it affects the Debt Intelligence System. We may ask the reporter for more information to help us reproduce the problem or understand the impact.
If the issue is a vulnerability, we will work to fix it as soon as possible. The time it takes to fix the vulnerability depends on the complexity of the fix and the severity of the vulnerability. We will keep the reporter informed of our progress.
Once the vulnerability is fixed, we will disclose it to the public. We will publish a security advisory and notify our users of the fix. We will also credit the reporter for their discovery if they chose to be credited.