Skip to content

Security: effatico/endex

Security

SECURITY.md

Security Policy

Effati Consulting takes the security of our software seriously. This policy applies to all public repositories under the effatico organization.

Supported Versions

Unless a repository states otherwise, we support the latest released version on the default branch. Security fixes are released as patch versions.

Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities.

Report privately using either channel:

  1. GitHub Private Vulnerability Reporting (preferred) — open the affected repository, go to Security → Report a vulnerability.
  2. Emailinfo@effati.se with the subject SECURITY: <repository name>.

Please include as much of the following as you can:

  • Affected repository, version, and platform
  • A description of the vulnerability and its impact
  • Steps to reproduce, ideally a minimal proof of concept
  • Any suggested mitigation or fix

What to Expect

Stage Target
Acknowledgement of your report within 3 business days
Initial assessment and severity triage within 7 business days
Fix or documented mitigation within 90 days, sooner for high severity

We will keep you updated as we work through triage and remediation, and we are happy to credit you in the release notes unless you prefer to stay anonymous.

Scope

In scope: source code, build and release tooling, and published packages in public effatico repositories.

Out of scope: findings that require a compromised host or account, reports generated solely by automated scanners without demonstrated impact, denial of service through unrealistic resource exhaustion, and vulnerabilities in third-party dependencies that already have a public advisory and no exploit path in our code.

Safe Harbour

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before public disclosure.

There aren't any published security advisories