Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Security: ctrf-io/ctrf

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public issue.

Instead, report it using one of the following private channels:

If your report contains sensitive information, please note this in the subject line.

Scope

This security policy applies to:

  • The CTRF specification
  • Reference implementations
  • Official repositories under the CTRF organization

Third-party dependencies should be reported to their respective maintainers.

Response Process

We aim to:

  • Acknowledge reports within 3 business days
  • Provide a status update as the investigation progresses
  • Coordinate a fix and responsible disclosure when appropriate

We appreciate responsible disclosure and will work with reporters in good faith.

There aren't any published security advisories

Morty Proxy This is a proxified and sanitized view of the page, visit original site.