Skip to content

Security: cloudsnacks/containers

Security

SECURITY.md

Security Policy

Supported Versions

We release patches for security vulnerabilities in the following versions:

Version Supported
latest
< latest

Reporting a Vulnerability

We take security seriously at CloudSnacks. If you discover a security vulnerability, please follow these steps:

Please DO NOT:

  • Open a public GitHub issue
  • Disclose the vulnerability publicly before it has been addressed

Please DO:

  1. Email us: Send details to [security@cloudsnacks.io] (or create a security advisory on GitHub)
  2. Provide details: Include as much information as possible:
    • Type of vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)
  3. Wait for acknowledgment: We'll respond within 48 hours

What to Expect

  • Acknowledgment: We'll confirm receipt within 48 hours
  • Updates: We'll keep you informed about our progress
  • Resolution: We'll work to address the issue promptly
  • Credit: We'll acknowledge your contribution (unless you prefer to remain anonymous)

Security Best Practices

When using CloudSnacks projects:

  • Keep dependencies up to date
  • Use secrets management for sensitive data
  • Follow principle of least privilege
  • Enable audit logging
  • Regularly review security configurations
  • Use official releases only

Bug Bounty Program

We currently do not have a bug bounty program, but we deeply appreciate security researchers who help keep CloudSnacks safe.

Thank you for helping keep CloudSnacks and our users safe! 🔒

There aren't any published security advisories