Skip to content

Security: joseph0926/prompt-smith

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.x.x
< 2.0

Reporting a Vulnerability

If you discover a security vulnerability, please report it by opening a GitHub issue with the label security.

For sensitive issues, contact the maintainer directly.

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Initial response: within 48 hours
  • Status update: within 7 days
  • Resolution target: within 30 days (depends on severity)

Security Best Practices

This project follows these security practices:

  1. No secrets in code - All sensitive data should be handled via environment variables
  2. Input validation - All user inputs are treated as untrusted data
  3. Dependency updates - Dependencies are regularly reviewed and updated

Scope

This security policy applies to the prompt-smith project and its official distributions.

There aren’t any published security advisories