Skip to content

Security: Morphological-Source-Code/.github

Security

SECURITY.md

root .github
name SECURITY.md
version 1.08
sentiment Bring it on!
difficulty Hurt me plenty
reward None, alternativley; exactly what you get out of it

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project Morphological Source Code: Cognosis, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, please email: MORPHOLOGIC@hotmail.com

Include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any suggested fixes (optional)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 7 days
  • Fix timeline: Per-case basis, based on severity and reporting requirements

Scope

Security issues in the following areas are in scope:

  • Local file access vulnerabilities
  • Remote code execution
  • CSP bypass issues (relevant to GitHub Pages deployment)
  • XSS vulnerabilities in the Feather Wiki runtime

Out of Scope

  • Issues requiring physical access to hardware (except the author's Ryzen 5600X in North America for physical validation, to be expanded in 1.x.y)
  • Nation-state actions or anything related to jurisprudence (no legal entity exists to sue; this is a spontaneous free contribution by a sole proprietor)
  • Social engineering attacks
  • Denial of Service attacks
  • Metadata sniffing/snooping
  • Adversarial environment issues (assuming "responsible computer use" in a non-adversarial environment; a fresh OS install on the author's CPU is a valid last-resort troubleshooting step)

Recognition

Researchers/Contributors who report valid security issues will be acknowledged in release notes (unless they prefer to remain anonymous) with top-5 listed in this file. No furthermore remuneration is associated with these acknowledgements.

Supported Versions

Version Supported
< 0.1.0 Unsupported
0.1.y Active development (supported, conditionally [see SECURITY.md ## Scope])
1.x.y (intended) Release schema (supported)

Top-5

    1. MOONLAPSED
    1. Phovos
    1. MORPHOLOGIC Org.: 'MSC&QSD'

There aren't any published security advisories