| root | .github |
|---|---|
| name | SECURITY.md |
| version | 1.08 |
| sentiment | Bring it on! |
| difficulty | Hurt me plenty |
| reward | None, alternativley; exactly what you get out of it |
If you discover a security vulnerability in this project Morphological Source Code: Cognosis, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please email: MORPHOLOGIC@hotmail.com
Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 7 days
- Fix timeline: Per-case basis, based on severity and reporting requirements
Security issues in the following areas are in scope:
- Local file access vulnerabilities
- Remote code execution
- CSP bypass issues (relevant to GitHub Pages deployment)
- XSS vulnerabilities in the Feather Wiki runtime
- Issues requiring physical access to hardware (except the author's Ryzen 5600X in North America for physical validation, to be expanded in 1.x.y)
- Nation-state actions or anything related to jurisprudence (no legal entity exists to sue; this is a spontaneous free contribution by a sole proprietor)
- Social engineering attacks
- Denial of Service attacks
- Metadata sniffing/snooping
- Adversarial environment issues (assuming "responsible computer use" in a non-adversarial environment; a fresh OS install on the author's CPU is a valid last-resort troubleshooting step)
Researchers/Contributors who report valid security issues will be acknowledged in release notes (unless they prefer to remain anonymous) with top-5 listed in this file. No furthermore remuneration is associated with these acknowledgements.
| Version | Supported |
|---|---|
| < 0.1.0 | Unsupported |
| 0.1.y | Active development (supported, conditionally [see SECURITY.md ## Scope]) |
| 1.x.y | (intended) Release schema (supported) |
-
- MOONLAPSED
-
- Phovos
-
- MORPHOLOGIC Org.: 'MSC&QSD'
-
-