Skip to content

Security: Cloudzero/template-cloudzero-open-source

SECURITY.md

Security Policy

Supported versions

This template does not ship a versioned product. Downstream projects should replace this table with the versions they still patch.

Version Supported
Latest main Yes

Reporting a vulnerability

Do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Preferred: GitHub private vulnerability reporting

If this repository has private vulnerability reporting enabled, use the Security tab → Advisories → Report a vulnerability (or open /security/advisories/new on this repo).

That keeps the report attached to the project and lets maintainers collaborate on a draft advisory before public disclosure.

Fallback: email

If private reporting is not enabled or you cannot use GitHub, email security@cloudzero.com.

What to include

  • Type of issue (for example XSS, injection, or privilege escalation)
  • Affected version, tag, commit, or URL
  • Full paths of the relevant source files
  • Any special configuration required to reproduce the issue
  • Step-by-step reproduction instructions
  • Proof of concept, if you can share one safely
  • Impact, including how an attacker might exploit the issue
  • Suggested mitigations, if you have them

Response process

After you submit a report, you can expect:

  1. An acknowledgment
  2. An assessment of the vulnerability and its impact
  3. Communication about the fix timeline
  4. Credit for your discovery (if you want it) when the issue is disclosed

Thank you for helping keep CloudZero and our users safe.

There aren't any published security advisories