Use GitHub private vulnerability reporting from the affected repository's
Security tab when it is available. Private vulnerability reporting is
enabled for Tinkora/.github; each product repository publishes its own
reporting status and supported versions.
Do not disclose a suspected vulnerability, exploit, secret, or affected user data in a public issue, pull request, Discussion, commit, or social post. If a verified private channel is not available, retain the minimum report and evidence securely and check this policy again. Tinkora does not publish a general-purpose private security email at this time.
A useful report includes the affected project and version or commit, impact, reproducible steps, minimal proof, and any known mitigation. Remove unrelated personal data and never submit live credentials.
Private vulnerability reporting is only for security vulnerabilities. It does not replace the separate conduct-reporting process described in CODE_OF_CONDUCT.md.
Tinkora does not promise a fixed response or remediation SLA. Reports are triaged according to impact, exploitability, affected users, and maintainer capacity. Publication and credit are coordinated only after the issue is understood and disclosure is safe.
Each project documents supported versions in its own security policy. Source availability alone is not a support promise, and projects without a stable release do not have a stable supported release line.
Operational details are defined in docs/SECURITY_OPERATIONS.md, and incidents follow docs/INCIDENT_RESPONSE.md.