Skip to content

Security: nowo-tech/PasswordPolicyBundle

Security

.github/SECURITY.md

Security Policy

Supported Versions

Version Supported
1.x

Reporting a Vulnerability

We take the security of PasswordPolicyBundle seriously. If you believe you have found a security vulnerability, please report it privately:

Please include:

  • Type of issue (e.g., injection, XSS, auth bypass, deserialization risk, etc.)
  • Affected file(s) and version/tag/commit
  • Steps to reproduce
  • Impact assessment
  • PoC (if available)

Response Timeline

  • Initial acknowledgment: within 48 hours
  • Follow-up status: within 7 days
  • Resolution: depends on complexity and impact

Disclosure Policy

  • We confirm receipt and validate the report.
  • We prepare and publish a fix as soon as possible.
  • We coordinate disclosure with the reporter.
  • We credit responsible disclosure (unless anonymity is requested).

Security Policy

Supported Versions

Version Supported
1.x

Reporting a Vulnerability

We take the security of PasswordPolicyBundle seriously. If you believe you have found a security vulnerability, please report it to us as described below.

How to Report

Please do not report security vulnerabilities through public GitHub issues.

Instead, please send an email to: hectorfranco@nowo.tech

Include the following information in your report:

  • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit it

Response Timeline

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution: Varies depending on complexity

Disclosure Policy

  • We will confirm receipt of your vulnerability report
  • We will work with you to understand and validate the issue
  • We will develop and release a fix as quickly as possible
  • We will publicly acknowledge your responsible disclosure (if desired)

Preferred Languages

We prefer all communications to be in English or Spanish.

Contact

There aren't any published security advisories