Skip to content

Security: flydev-fr/Blackhole

SECURITY.md

Security Policy

Reporting a Vulnerability

If you believe you have found a security vulnerability in the "Blackhole" module for ProcessWire, we highly appreciate your responsible disclosure. To report a security vulnerability, please follow these steps:

  1. Do Not create a public issue or disclose the vulnerability on public forums, blogs, or social media until it has been addressed and fixed.
  2. Privately Notify Us: Please send an email to security@sekretservices.com with all the details regarding the vulnerability you discovered.
  3. Include Details: In your email, provide a clear description of the vulnerability, the steps to reproduce it, and any relevant supporting information such as affected versions or configurations.
  4. Encryption: To encrypt your message, you can use our PGP key. Please request our PGP key in the initial email, and we will send it to you.
  5. Acknowledgment: After receiving your report, we will acknowledge the receipt of the vulnerability report as soon as possible and within 48 hours.
  6. Assessment: W will assess and investigate the reported vulnerability to verify its validity and impact.
  7. Fix and Disclosure: Once the vulnerability is verified and fixed, we will release an update addressing the issue. We will provide proper credit to you for responsible disclosure if you desire. We will also publish a security advisory to inform users of the vulnerability.

Issue Template (Optional)

If you prefer to submit the vulnerability report as an issue on our repository, please follow these guidelines:

  1. Title: Use a clear and concise title that describes the vulnerability (e.g., "XSS Vulnerability in Function ABC").
  2. Description: Provide detailed information about the vulnerability, including steps to reproduce it, affected versions, and potential impact.
  3. Affected Versions: List the module versions affected by the vulnerability.
  4. Proof of Concept: If possible, provide a proof-of-concept or code snippet that demonstrates the vulnerability.
  5. Any Other Relevant Information: Include any other information that may be helpful to understand the issue.

Please note that submitting the vulnerability report as an issue will make it publicly visible on the repository. If the vulnerability is severe, we encourage you to follow the private disclosure steps mentioned earlier.

Thank you for your cooperation and commitment to improving the security of the "Blackhole" module and the ProcessWire community.

There aren’t any published security advisories