Skip to content

Security: qualityruntime/runtime

.github/SECURITY.md

Security Policy

Security is important to Quality Runtime. If you believe you have found a security vulnerability, please report it privately.

Reporting a vulnerability

Email security@qualityruntime.com with:

  • a description of the vulnerability;
  • affected components, versions, or commits;
  • steps to reproduce or a proof of concept, when appropriate;
  • the potential impact;
  • any suggested remediation, if known.

Please do not open a public GitHub issue or otherwise disclose the vulnerability publicly before we have had a reasonable opportunity to investigate and address it.

We aim to acknowledge security reports within 5 business days and will coordinate with the reporter on remediation and disclosure as appropriate.

Supported versions

Quality Runtime is currently in early development and has no production-ready releases.

Until the first supported release is published, security fixes are applied to the current development version.

Responsible disclosure

Please make a good-faith effort to:

  • avoid accessing or modifying data that does not belong to you;
  • avoid disrupting services or systems;
  • avoid privacy violations or destructive testing;
  • keep vulnerability details confidential until remediation or coordinated disclosure.

We appreciate responsible security research and reports that help improve Quality Runtime.

Security architecture

For information about the project's security architecture and design principles, see docs/security.md.

There aren't any published security advisories