Skip to content

Security: stacklok/mecatl

Security

SECURITY.md

Security Policy

The mecatl community takes security seriously. We appreciate responsible reports that help protect users and operators.

Reporting a vulnerability

Please do not report security vulnerabilities in public GitHub issues. Report them privately through GitHub Security Advisories using Report a Vulnerability.

If you cannot access GitHub, email security@stacklok.com. Include steps to reproduce the issue, affected versions, and any files needed to reproduce it. If you need to use GPG, first email to request a public PGP key.

Disclosure

We ask reporters to use coordinated, private disclosure until a fix or mitigation is available. If you know of a publicly disclosed vulnerability, please notify security@stacklok.com promptly so we can assess and address it.

The security team will coordinate investigation, remediation, and public communication as appropriate for the vulnerability. For non-security bugs and contributions, see CONTRIBUTING.md.

There aren't any published security advisories