Effati Consulting takes the security of our software seriously. This policy applies to
all public repositories under the effatico organization.
Unless a repository states otherwise, we support the latest released version on the default branch. Security fixes are released as patch versions.
Please do not open a public issue for security vulnerabilities.
Report privately using either channel:
- GitHub Private Vulnerability Reporting (preferred) — open the affected repository, go to Security → Report a vulnerability.
- Email — info@effati.se with the subject
SECURITY: <repository name>.
Please include as much of the following as you can:
- Affected repository, version, and platform
- A description of the vulnerability and its impact
- Steps to reproduce, ideally a minimal proof of concept
- Any suggested mitigation or fix
| Stage | Target |
|---|---|
| Acknowledgement of your report | within 3 business days |
| Initial assessment and severity triage | within 7 business days |
| Fix or documented mitigation | within 90 days, sooner for high severity |
We will keep you updated as we work through triage and remediation, and we are happy to credit you in the release notes unless you prefer to stay anonymous.
In scope: source code, build and release tooling, and published packages in public
effatico repositories.
Out of scope: findings that require a compromised host or account, reports generated solely by automated scanners without demonstrated impact, denial of service through unrealistic resource exhaustion, and vulnerabilities in third-party dependencies that already have a public advisory and no exploit path in our code.
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before public disclosure.