Skip to content

Security: nexlabz/.github

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please don't open a public issue for a security problem.

Report it privately through GitHub Security Advisories — use the advisory form on the specific repo if the issue is in one — or email security@nexlabz.dev.

Helpful to include:

  • What the issue is and roughly how bad you think it is
  • Steps to reproduce, or a proof of concept
  • The affected repo, version, or deployment
  • Anything you think we'd get wrong about the impact

What happens next

When What
Within 3 working days We acknowledge your report
Within 10 working days We confirm the issue and give you an assessment
After a fix ships We publish an advisory and credit you, unless you'd rather we didn't

If you don't hear from us in the first window, please chase us — a missed email is far more likely than a deliberate silence.

Scope

Anything in a public nexlabz repo, and any service we run at a nexlabz.dev domain.

Several projects here are clearly-labelled experiments rather than production software. We still want to know about problems in them, but our fix timeline will reflect what the project actually is.

Out of scope: findings from automated scanners with no demonstrated impact, missing hardening headers with no exploit path, social engineering, and anything requiring physical access to a user's machine.

Our commitment

Report in good faith and we won't pursue or support legal action against you. Please give us reasonable time to fix an issue before disclosing it publicly, and don't access, modify, or destroy data that isn't yours while testing.

There aren't any published security advisories