Skip to content

Security: ldapwarden/.github

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release of LDAPWarden receives security updates.

Version Supported
Latest
< Latest

Reporting a Vulnerability

We take the security of LDAPWarden seriously. If you discover a security vulnerability, please report it responsibly.

Please do NOT report security vulnerabilities through public GitHub issues, discussions, or pull requests.

Instead, please send an email to security@ldapwarden.org.

What to Include

To help us triage and prioritize your report, please include as much of the following as possible:

  • A description of the vulnerability
  • The affected component (e.g., module, function, endpoint)
  • Step-by-step instructions to reproduce the issue
  • The potential impact of the vulnerability
  • Any possible mitigations you have identified
  • Your name and affiliation (if you would like to be credited)

What to Expect

  • Acknowledgement: We will acknowledge receipt of your report within 72 hours.
  • Assessment: We will evaluate the vulnerability and determine its severity and impact.
  • Updates: We will keep you informed of our progress toward a fix.
  • Disclosure: Once the issue is resolved, we will coordinate with you on responsible disclosure.

Disclosure Policy

  • We follow a coordinated disclosure process.
  • We ask that you give us a reasonable amount of time to address the issue before any public disclosure.
  • We will credit reporters who follow responsible disclosure, unless they prefer to remain anonymous.

Security Best Practices for Contributors

  • Never commit secrets, credentials, or API keys to the repository.
  • Keep dependencies up to date and review them for known vulnerabilities.
  • Follow the principle of least privilege in code and configuration.

Thank you for helping keep LDAPWarden and its users safe.

There aren't any published security advisories